GitHub Paid Out $1.5 Million in Bug Bounties in 2022

Microsoft-owned code hosting platform GitHub on Tuesday announced that it paid out more than $1.57 million in rewards through its bug bounty program between February 2022 and February 2023.

As part of the program, which has been running on the HackerOne platform since 2016, GitHub handed out a total of over $3.8 million in bug bounty rewards.

Last year, the code hosting platform received more than 2,000 vulnerability reports and awarded bounties for 364 security defects. The highest number of submissions was registered in June 2022, during its H1-512 live hacking event in Austin.

A total of 45 in-person and remote researchers participated in the hacking event. Roughly half of the 182 received submissions were validated and GitHub handed out close to $700,000 in bug bounties.

“H1-512 was a fantastic opportunity for our team to experience the excitement and passion of our hackers in person. This event enabled us to break down the barriers of the screen and to make meaningful connections,” GitHub says.

The platform started a limited disclosure of reports for vulnerabilities in GitHub Enterprise Server (GHES) and open source projects that receive a CVE identifier, and plans to disclose more reports via HackerOne.

Additionally, GitHub continues to find new ways to expand its rewards for the reporting researchers, and says it will complement eligible submissions with non-monetary rewards to attract more white hat hackers to its bug bounty program.

Advertisement. Scroll to continue reading.

“We encourage researchers of all levels to submit reports to our bug bounty program. Your submissions are greatly valued and impactful to ensuring the safety and security of our products, our users, and the community,” GitHub notes.

Related: GitHub Warns of North Korean Social Engineering Attacks Targeting Tech Firm Employees

Related: GitHub Secret-Blocking Feature Now Generally Available

Related: GitHub Announces New Security Improvements

https://www.securityweek.com/github-paid-out-1-5-million-in-bug-bounties-in-2022/




Chrome 116 Patches 26 Vulnerabilities

Google on Tuesday announced the release of Chrome 116 to the stable channel with patches for 26 vulnerabilities, including 21 reported by external researchers.

Of the externally reported bugs, eight have a severity rating of ‘high’, with most of them being memory safety issues.

Based on the bug bounty reward paid out, the most important of these is CVE-2023-2312, a use-after-free flaw in the Offline component. The reporting researcher was awarded a $30,000 bounty for the finding, Google’s advisory reveals.

Next in line is CVE-2023-4349, a use-after-free issue in Device Trust Connectors, followed by an inappropriate implementation in Fullscreen (CVE-2023-4350), and a use-after-free bug in Network (CVE-2023-4351), for which Google paid out bounties of $5,000, $3,000, and $2,000, respectively.

The remaining four high-severity vulnerabilities that Chrome 116 resolves include a type confusion flaw in the V8 JavaScript engine, a heap buffer overflow bug in ANGLE, another in Skia, and an out-of-bounds memory access issue in the V8 engine.

These issues were reported by researchers at Google Project Zero and Microsoft Vulnerability Research and, per Google’s policy, no bug bounty reward will be issued for them.

All the remaining externally-reported vulnerabilities addressed in Chrome 116 are medium-severity: six inappropriate implementation bugs, three use-after-free issues, two insufficient policy enforcement flaws, one insufficient validation of untrusted input, and one heap buffer overflow vulnerability.

Advertisement. Scroll to continue reading.

Overall, Google handed out $63,000 in bug bounty rewards to the reporting researchers.

The internet giant makes no mention of any of these vulnerabilities being exploited in attacks.

The latest Chrome iteration is rolling out as version 116.0.5845.96 for Mac and Linux and as versions 116.0.5845.96/.97 for Windows.

Starting with Chrome 116, the internet giant announced last week, patches for the popular browser will be shipped on a weekly basis, to ensure that fixes for newly discovered flaws reach users faster.

Major Chrome iterations will continue to arrive every four weeks, but stable updates, which have been released every two weeks since 2020, will now be more frequent, reducing the patch gap.

“While we can’t fully remove the potential for n-day exploitation, a weekly Chrome security update cadence allows up to ship security fixes 3.5 days sooner on average, greatly reducing the already small window for n-day attackers to develop and use an exploit against potential victims and making their lives much more difficult,” Google said.

Related: Google Awards Over $60,000 for V8 Vulnerabilities Patched With Chrome 115 Update

Related: Chrome 115 Patches 20 Vulnerabilities

Related: Chrome and Its Vulnerabilities – Is the Web Browser Safe to Use?

https://www.securityweek.com/chrome-116-patches-26-vulnerabilities/




2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability

A threat actor has automated the exploitation of a recent Citrix vulnerability and has infected roughly 2,000 NetScaler instances with a backdoor, British information assurance firm NCC Group reports.

Tracked as CVE-2023-3519, the critical vulnerability was disclosed last month as a zero-day, being exploited since June 2023, including in attacks against critical infrastructure organizations.

The issue allows unauthenticated, remote attackers to execute arbitrary code on vulnerable Citrix Application Delivery Controller (ADC) and Gateway appliances that are configured as a gateway or AAA virtual server.

Roughly a week after Citrix released patches for the bug, cybersecurity firm Bishop Fox warned that it had identified more than 20,000 Citrix appliances vulnerable to a new exploit.

Now, NCC Group says it has observed an automated exploitation campaign in which more than 1,950 NetScaler instances were compromised, representing roughly 6.3% of the 31,000 vulnerable appliances identified at the beginning of the exploitation campaign.

The company identified close to 2,500 webshells on the compromised instances, and says that more than 1,800 of them remain infected. Starting August 10, the Dutch Institute of Vulnerability Disclosure has been notifying the impacted organizations of NCC Group’s findings.

More worrying, the cybersecurity firm says, is that roughly 69% of the infections occurred before the impacted organizations applied the provided patch. However, the backdoor has not been removed.

Advertisement. Scroll to continue reading.

“This indicates that while most administrators were aware of the vulnerability and have since patched their NetScalers to a non-vulnerable version, they have not been (properly) checked for signs of successful exploitation,” NCC Group says.

The large number of NetScaler instances infected before being patched also shows that the mass exploitation campaign took place around the same time that Citrix released the fixes.

“The high percentage of patched NetScalers that have been backdoored is likely a result of the time at which mass exploitation took place. From incident response cases, we can confirm Shadowserver’s prior estimate that this specific exploitation campaign took place between late July 20th and early July 21st,” NCC Group notes.

Mandiant on Monday released a tool to help organizations scan their Citrix appliances for evidence of post-exploitation activity related to CVE-2023-3519. Google-owned Mandiant says the tool, available on GitHub, contains indicators of compromise (IOCs) collected during Mandiant’s investigations and sourced elsewhere.

Most of the identified infections are in Europe, with Germany, France, and Switzerland impacted the most. Japan and Italy round up the top five. Canada, Russia, and the US have virtually no infected NetScaler instances.

*Updated with details of tool released by Mandiant

Related: Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins

Related: Citrix Patches Critical Vulnerability in Secure Access Client for Ubuntu

Related: Citrix Patches High-Severity Vulnerabilities in Windows, Linux Apps

https://www.securityweek.com/2000-citrix-netscaler-instances-backdoored-via-recent-vulnerability/




Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying

Vulnerabilities in power management products made by CyberPower and Dataprobe could be exploited in attacks aimed at data centers, allowing threat actors to spy on organizations or cause damage, according to threat detection and response firm Trellix. 

Trellix researchers have analyzed CyberPower’s PowerPanel Enterprise data center power management software and Dataprobe’s iBoot power distribution unit (PDU). They discovered a total of nine vulnerabilities, including ones allowing an attacker to gain full access to the targeted system.

Previous research showed that many PDUs, including the iBoot product, are often exposed to the internet, making it possible to launch remote attacks against organizations using them.   

In the CyberPower PowerPanel Enterprise product, Trellix researchers discovered four vulnerabilities, including hardcoded credentials, authentication bypass, and OS command injection issues. 

In the Dataprobe iBoot PDU, they identified five vulnerabilities, indcluding OS command injection, authentication bypass, hardcoded credentials, and denial-of-service (DoS) issues. 

In real world attacks, threat actors could exploit these types of vulnerabilities to cut power to connected devices and cause significant disruption. 

“A threat actor could cause significant disruption for days at a time with the simple ‘flip of a switch’ in dozens of compromised data centers,” Trellix warned. 

Advertisement. Scroll to continue reading.

“Furthermore, manipulation of the power management can be used to damage the hardware devices themselves – making them far less effective if not inoperable,” it added, noting that this could result in financial losses of thousands or tens of thousands of dollars for every minute the data center’s power is down. 

In addition to directly causing damage or disruption, hackers could plant backdoors on the data center equipment and use them to compromise other systems and devices. 

“Some data centers host thousands of servers and connect to hundreds of various business applications. Malicious attackers could slowly compromise both the data center and the business networks connected to it,” Trellix said.

Compromised data center power management systems could also be leveraged by state-sponsored threat actors to conduct cyberespionage. 

CyberPower and Dataprobe have been notified and both vendors have released updates to patch the vulnerabilities. In addition to installing the patches, organizations are advised to ensure that their systems are not exposed to the internet. 

Trellix said it was not aware of any malicious attacks exploiting these vulnerabilities. 

Related: Exploited Solar Power Product Vulnerability Could Expose Energy Organizations to Attacks

Related: Security Firm Finds Over 130k Internet-Exposed Photovoltaic Diagnostics Systems

https://www.securityweek.com/power-management-product-flaws-can-expose-data-centers-to-damaging-attacks-spying/




Ford Says Wi-Fi Vulnerability Not a Safety Risk to Vehicles

American car maker Ford says that a vulnerability in the Wi-Fi driver of the SYNC 3 infotainment system on certain Ford and Lincoln vehicles does not pose a safety risk.

Tracked as CVE-2023-29468, the bug impacts the Texas Instruments-supplied Wi-Fi driver used in the infotainment system of at least a dozen vehicles.

The issue is described as a buffer overflow that could lead to remote code execution. An attacker within wireless range of an impacted device can trigger the flaw using a specially crafted frame.

In its advisory, TI explains that the CVSS score of the vulnerability ranges from 8.8 to 9.6, depending on the confidentiality and integrity impact of affected systems.

In response to TI’s disclosure of the bug, Ford announced that it has been working with the chip maker to develop and validate “measures to address the vulnerability”.

“To date, we’ve seen no evidence that this vulnerability has been exploited, which would likely require significant expertise and would also include being physically near an individual vehicle that has its ignition and Wi-Fi setting on,” Ford says.

The vehicle manufacturer also notes that, even if exploited, the vulnerability does not pose a threat to “the safety of vehicle occupants, since the infotainment system is firewalled from controls like steering, throttling and braking”. 

Advertisement. Scroll to continue reading.

The company says a software patch will soon become available for download and installation via the cars’ USB ports and recommends that vehicle owners turn off the Wi-Fi.

“In the interim, customers who are concerned about the vulnerability can simply turn off the Wi-Fi functionality through the SYNC 3 infotainment system’s Settings menu. Customers can also find out online if their vehicles are equipped with SYNC 3,” Ford notes.

According to Ford, the SYNC 3 infotainment system is available on 2021’s Mustang, Super Duty, Transit, Transit Connect, Bronco Sport, Expedition, Explorer, Escape, and EcoSport models, and on 2022’s Mustang, Super Duty Retail, Transit, Transit Connect, Maverick, Ranger, Bronco Sport, Explorer, Escape, and EcoSport models.

Related: Toyota Discloses New Data Breach Involving Vehicle, Customer Information

Related: 16 Car Makers and Their Vehicles Hacked via Telematics, APIs, Infrastructure

Related: Researchers Hack Remote Keyless System of Honda Vehicles

https://www.securityweek.com/ford-says-wi-fi-vulnerability-not-a-safety-risk-to-vehicles/




Iagona ScrutisWeb Vulnerabilities Could Expose ATMs to Remote Hacking

Several vulnerabilities discovered in the ScrutisWeb ATM fleet monitoring software made by French company Iagona could be exploited to remotely hack ATMs. 

The security holes were discovered by Synack Red Team members and they were patched by the vendor in July 2023 with the release of ScrutisWeb version 2.1.38. 

ScrutisWeb allows organizations to monitor banking or retail ATM fleets from a web browser, enabling them to quickly respond to problems. The solution can be used to monitor hardware, reboot or shut down a terminal, send and receive files, and modify data remotely. It’s worth noting that ATM fleets can include check deposit machines and payment terminals in a restaurant chain. 

The Synack researchers identified four types of vulnerabilities that have been assigned the CVE identifiers CVE-2023-33871, CVE-2023-38257, CVE-2023-35763 and CVE-2023-35189. 

The flaws include path traversal, authorization bypass, hardcoded cryptographic key, and arbitrary file upload issues that can be exploited by remote, unauthenticated attackers.

Threat actors could exploit the flaws to obtain data from the server (configurations, logs and databases), execute arbitrary commands, and obtain encrypted administrator passwords and decrypt them using a hardcoded key. 

The researchers said an attacker can leverage the flaws to log into the ScrutisWeb management console as an admin and monitor the activities of connected ATMs, enable management mode on the devices, upload files, and reboot or power them off.

Advertisement. Scroll to continue reading.

Hackers could also exploit the remote command execution vulnerability to hide their tracks by deleting relevant files.

“Additional exploitation from this foothold in the client’s infrastructure could occur, making this an internet-facing pivot point for a malicious actor,” explained Neil Graves, one of the researchers involved in this project.

“Further examination would be required to determine if custom software could be uploaded to individual ATMs to perform bank card exfiltration, Swift transfer redirection, or other malicious activities. However, such additional testing was out of scope of the assessment,” Graves said.

The US Cybersecurity and Infrastructure Security Agency (CISA) recently published an advisory to inform organizations about these vulnerabilities. According to CISA, the impacted product is used worldwide.

Related: Millions Stolen in Hack at Cryptocurrency ATM Manufacturer General Bytes

Related: New ATM Malware ‘FiXS’ Emerges

Related: Diebold Nixdorf ATM Flaws Allowed Attackers to Modify Firmware, Steal Cash

https://www.securityweek.com/iagona-scrutisweb-vulnerabilities-could-expose-atms-to-remote-hacking/




In Other News: macOS Security Reports, Keyboard Spying, VPN Vulnerabilities

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:   

Stealing data by listening to the sound of keystrokes

Researchers have shown how an AI model can accurately determine the key that is being pressed on a keyboard based on the sound that it makes. They demonstrated how an attacker could steal sensitive information by using a phone or Zoom to record the sound of keystrokes, with an accuracy of over 90%.

DHS announces additional cybersecurity funding

Advertisement. Scroll to continue reading.

The DHS has announced an additional $374 million available in grant funding for state and local governments to boost their cyber resilience. The funding is offered as part of the State and Local Cybersecurity Grant Program (SLCGP) for FY 2023. 

Interpol shuts down phishing platform

Interpol announced the shutdown of a notorious phishing-as-a-service platform named 16shop. As part of the operation, authorities in Indonesia and Japan arrested individuals believed to have been involved in the cybercrime scheme. 

Department of Health and Human Services issues alert on Rhysida ransomware

The US Department of Health and Human Services has issued an alert to warn healthcare organizations about an emerging ransomware-as-a-service (RaaS) group named Rhysida. Victims have been observed in the Americas, western Europe and Australia across several sectors.

New ransomware groups emerging due to code leaks

Cisco Talos reported that there has been an influx of new ransomware groups due to leaked source code or builders. These new threat actors are demanding low ransom payments compared to prominent groups. 

Chinese state-sponsored threat group RedHotel

A Chinese state-sponsored threat group named RedHotel has targeted entities in the academia, aerospace, media, government, research, and telecom sectors in the past couple of years. Victims have been seen in 17 countries in Asia, Europe and North America, but the group’s focus appears to be Southeast Asia, according to a new report from Recorded Future. 

macOS security reports

macOS security reports were published this week by Accenture and Bitdefender. Bitdefender data shows that Mac users are mainly targeted by trojans, adware, and potentially unwanted applications (PUAs). Accenture reported seeing a 1000% increase in dark web threat actors targeting macOS. 

Cybersecurity gaps found in all companies backed by London’s biggest VC firms 

DynaRisk has conducted an analysis of 5,482 companies backed by London’s biggest venture capital firms, and found that every single one of them had issues that could leave them exposed to cyberattacks. Two-thirds had high-risk vulnerabilities and nearly 9% had critical security holes. 

Google to release Chrome security updates more frequently

Google has announced that starting with Chrome 116 it plans on shipping weekly stable channel updates in an effort to get security fixes to users more quickly. 

TunnelCrack VPN vulnerabilities

Researchers have released the details of a VPN attack named TunnelCrack, which uses a combination of two vulnerabilities that allow attackers to intercept traffic outside the VPN tunnel. Tests showed that every VPN product is vulnerable on at least one device. Exploitation is possible when a user connects to an untrusted Wi-Fi network and in some cases through malicious ISPs.

NCC Group laying off more staff

UK cybersecurity firm NCC Group is laying off a “small number” of employees after earlier this year it announced plans to terminate 125 workers in the UK and North America. Rapid7 also announced layoffs this week. 

Zyxel routers targeted via old vulnerability

Discontinued Zyxel routers are being targeted through the exploitation of a vulnerability patched by the vendor in 2017. CISA this week added the flaw to its ‘must patch’ list and Fortinet has reported seeing thousands of attack attempts

Related: In Other News: Cybersecurity Funding Rebounds, Cloud Threats, BeyondTrust Vulnerability

https://www.securityweek.com/in-other-news-macos-security-reports-keyboard-spying-vpn-vulnerabilities/




CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio 

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a zero-day flaw affecting Microsoft’s .NET and Visual Studio products to its Known Exploited Vulnerabilities Catalog. 

The vulnerability, tracked as CVE-2023-38180, was fixed by Microsoft with its August 2023 Patch Tuesday updates, which also address CVE-2023-36884, an Office vulnerability exploited by Russian threat actors.  

CVE-2023-38180 can be exploited for denial-of-service (DoS) attacks, and Microsoft noted in its advisory that it’s aware of malicious exploitation. No details are available on the attacks leveraging the vulnerability.

Microsoft’s advisory reveals that remote exploitation is possible and no user interaction or privileges are required.

The vulnerability has been assigned an ‘important’ severity rating and a CVSS score of 7.5 (high severity). According to Microsoft, it impacts Visual Studio 2022 versions 17.2, 17.4 and 17.6, as well as .NET 6.0 and 7.0, and ASP.NET Core 2.1. 

CISA has added CVE-2023-38180 to its so-called ‘must patch’ list, instructing government organizations to apply patches or mitigations by August 30, as per Binding Operational Directive 22-01.

CISA’s catalog also includes a few other exploited vulnerabilities affecting .NET and/or Visual Studio.  

Advertisement. Scroll to continue reading.

Related: Microsoft SmartScreen Zero-Day Exploited to Deliver Magniber Ransomware

Related: Microsoft Warns of Office Zero-Day Attacks, No Patch Available

Related: Microsoft Patch Tuesday: 40 Vulnerabilities, 2 Zero-Days

https://www.securityweek.com/cisa-warns-organizations-of-exploited-vulnerability-in-net-visual-studio/




Western Digital, Synology NAS Vulnerabilities Exposed Millions of Users’ Files

Critical vulnerabilities discovered by IoT and industrial cybersecurity firm Claroty in Western Digital (WD) and Synology network-attached storage (NAS) products could have exposed the files of millions of users.

The vulnerabilities and their exploitation was demonstrated at the Zero Day Initiative’s Pwn2Own Toronto hacker contest in December 2022, where participants earned a total of nearly $1 million for hacking smartphones, printers, routers, NAS devices, and smart speakers.

Both vendors have pushed out patches (in some cases automatically) and published advisories to inform customers about the vulnerabilities. Synology released one advisory and WD published three advisories, in December, January and May.

In the case of WD, Claroty researchers found a way to enumerate all cloud-connected NAS devices, impersonate them, and gain access to each system through the vendor’s MyCloud service. An attacker could have exploited the vulnerabilities to remotely access user files, execute arbitrary code, and take full control of cloud-connected devices. 

“First, we enumerate all of the devices GUID, and choose our target list. We then impersonate the device, stealing its cloud tunnel and disconnecting the device. Any requests performed to the device will now reach us, giving us the authentication tokens for the device admin,” Claroty explained. 

It added, “Using our newly gained permissions, we created a new share on the device, mapping it to the /tmp directory. We then write our reverse shell payload to that directory, and invoke a reboot through the cloud. Whenever the device will reboot, our payload will be executed, resulting in us executing code on the device.”

The cybersecurity firm also found vulnerabilities that allowed it to impersonate Synology NAS devices and force the QuickConnect cloud service to redirect users to a device controlled by the attacker. 

Advertisement. Scroll to continue reading.

An attacker could have leveraged the flaws to steal credentials, access user data, and remotely execute arbitrary code, giving them control over the device and the ability to launch further attacks. 

Claroty’s analysis showed that millions of WD and Synology NAS devices were vulnerable to attacks. 

Both the WD and Synology exploits were possible due to “weak device authentication based on publicly known information rather than secrets”, and Claroty believes similar issues likely impact devices from other vendors as well.

The company has published separate blog posts describing the WD and Synology vulnerabilities. 

Related: CISA Says Critical Zyxel NAS Vulnerability Exploited in Attacks

Related: 30k Internet-Exposed QNAP NAS Devices Affected by Recent Vulnerability

Related: QNAP Warns of New ‘Deadbolt’ Ransomware Attacks Targeting NAS Users

https://www.securityweek.com/western-digital-synology-nas-vulnerabilities-exposed-millions-of-users-files/




Microsoft Paid Out $13 Million via Bug Bounty Programs for Fourth Consecutive Year

For the fourth consecutive year, Microsoft has announced paying out more than $13 million through its bug bounty programs.

The tech giant revealed this week that it awarded a total of $13.8 million to 345 researchers from more than 45 countries between July 1, 2022, and June 30, 2023. The money was paid out for more than 1,100 vulnerability reports, with the highest single reward reaching $200,000. 

Microsoft announced paying out similar amounts in 2020, 2021 and 2022

The company is running 17 bug bounty programs, a majority for its cloud services and platforms. Researchers are also being offered significant rewards as part of grants and challenges.

The highest reward — up to $250,000 — has been offered for critical vulnerabilities found in the Hyper-V hypervisor.

Since the beginning of the year, Microsoft announced new high-impact scenarios for the Microsoft 365 Insider Builds on Windows program, Teams Preview and Bing bug bounty research invitation challenges, and the addition of secure boot research scenarios to the Windows Insider Preview program.

Other tech giants have also paid out millions through their bug bounty programs. The latest available data shows that Facebook parent Meta paid $16 million since 2011, Google paid $12 million in 2022, Intel paid $4.1 million since 2017, and Apple paid $20 million since 2016. 

Advertisement. Scroll to continue reading.

Related: Hacker Conversations: Youssef Sammouda, Bug Bounty Hunter

Related: Google Launches Bug Bounty Program for Mobile Applications

Related: SquareX Launches Bug Bounty Program for Browser Security Product

Related: Adobe Inviting Researchers to Private Bug Bounty Program

https://www.securityweek.com/microsoft-paid-out-13-million-via-bug-bounty-programs-for-fourth-consecutive-year/