Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities

Government agencies in Australia, Canada, New Zealand, the UK, and the US have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.

Last year, the Five Eyes agencies say, threat actors mainly targeted internet-facing systems that were not patched against older, known vulnerabilities, including flaws for which proof-of-concept (PoC) exploit code exists publicly.

“Malicious cyber actors generally have the most success exploiting known vulnerabilities within the first two years of public disclosure—the value of such vulnerabilities gradually decreases as software is patched or upgraded. Timely patching reduces the effectiveness of known, exploitable vulnerabilities, possibly decreasing the pace of malicious cyber actor operations,” the agencies note.

Threat actors, the agencies say, likely focus on exploits for severe vulnerabilities that have wider impact, which provides them with “low-cost, high-impact tools” that can be used for years, and prioritize exploits for bugs impacting the networks of their specific targets.

Throughout 2022, the reporting agencies observed the frequent exploitation of 12 vulnerabilities, some of which were exploited in previous attacks as well, although patches have been available for years.

The list includes CVE-2018-13379 (Fortinet SSL VPNs), CVE-2021-34473, CVE-2021-31207, CVE-2021-34523 (Microsoft Exchange, ProxyShell), CVE-2021-40539 (Zoho ManageEngine ADSelfService Plus), CVE-2021-26084, CVE-2022-26134 (Atlassian Confluence), CVE-2021- 44228 (Log4Shell), CVE-2022-22954, CVE-2022-22960 (VMware products), CVE-2022-1388 (F5 BIG-IP), and CVE-2022-30190 (Windows, Follina).

Additionally, the Five Eyes agencies call attention to 30 other known vulnerabilities that were routinely exploited in attacks in 2022, in products from Apache, Citrix, F5 Networks, Fortinet, Ivanti, Microsoft, Oracle, QNAP, SAP, SonicWall, VMware, WSO2, and Zimbra.

Advertisement. Scroll to continue reading.

Vendors and developers are advised to audit their environments to identify classes of exploited vulnerabilities and eliminate them, implement secure design practices, prioritize secure-by-default configurations, and follow Secure Software Development Framework (SSDF).

End-user organizations are advised to apply available software updates and patches in a timely manner, perform secure system backups, maintain a cybersecurity incident response plan, implement robust identity and access management policies, ensure that internet-facing network devices are secured, implement Zero Trust Network Architecture (ZTNA), and improve their supply-chain security.

Related: CISA Tells US Agencies to Patch Exploited Roundcube, VMware Flaws

Related: CISA: Several Old Linux Vulnerabilities Exploited in Attacks

Related: 670 ICS Vulnerabilities Disclosed by CISA in First Half of 2023: Analysis

https://www.securityweek.com/five-eyes-agencies-call-attention-to-most-frequently-exploited-vulnerabilities/




Dozens of RCE Vulnerabilities Impact Milesight Industrial Router

Dozens of vulnerabilities impacting the Milesight UR32L industrial router could be exploited to execute arbitrary code or commands, Cisco’s Talos security researchers warn.

A cost-effective solution, the UR32L router provides WCDMA and 4G LTE support, Ethernet ports, and remote device management, which make it suitable for a broad range of M2M/IoT applications.

During their investigation into the UR32L router and the accompanying remote access solution MilesightVPN, Talos submitted more than 20 vulnerability reports that resulted in 69 CVEs being assigned. Of these, 63 impact the industrial router.

The most severe of the identified issues is CVE-2023-23902 (CVSS score of 9.8), described as a buffer overflow vulnerability in the HTTP server login functionality of the router, which could lead to remote code execution (RCE) via network requests.

“This is the most severe vulnerability found on the router. Indeed, it is a pre-authentication remote stack-based buffer overflow. An unauthenticated attacker able to communicate with the HTTP server would be able to perform remote command execution,” Talos says.

Except two bugs, the remaining vulnerabilities impacting the UR32L router are high-severity flaws, most of which could lead to arbitrary code execution or command execution.

The vulnerabilities impacting the MilesightVPN application, Talos says, can be exploited to execute commands, read arbitrary files, bypass authentication, and inject arbitrary Javascript code.

Advertisement. Scroll to continue reading.

The vendor is providing the MilesightVPN as means to ensure that the UR32L router is not exposed to the internet, thus reducing attack surface.

According to Talos, however, an attacker could exploit an authentication bypass in the VPN software (tracked as CVE-2023-22319) and then execute arbitrary code on the device, by exploiting CVE-2023-23902.

Talos also notes that the discovered vulnerabilities were reported to the vendor in February 2023, but that no software update has been released to address them. SecurityWeek has emailed Milesight for a statement on the matter.

The flaws in the Milesight router, Talos says, were found as part of a broader research initiative focused on SOHO router bugs, which has led to the discovery of 289 vulnerabilities over the course of five years.

Triggered by the discovery of the VPNFilter malware in 2018, the research also identified issues in router models from Asus, D-Link, InHand Network, Linksys, Netgear, Robustel, Sierra Wireless, Siretta, Synology, TCL, TP-Link, and ZTE, as well as in OpenWrt, FreshTomato, Asuswrt, and NetUSB.ko.

Aside from the Milesight vulnerabilities, however, the rest of the identified security defects were publicly disclosed between 2018 and 2022.

Related: Asus Patches Highly Critical WiFi Router Flaws

Related: Enterprises Exposed to Hacker Attacks Due to Failure to Wipe Discarded Routers

Related: Newly Disclosed Vulnerability Exposes EOL Arris Routers to Attacks

https://www.securityweek.com/dozens-of-rce-vulnerabilities-impact-milesight-industrial-router/




These Are the Top Five Cloud Security Risks, Qualys Says

Cloud security specialist Qualys has provided its view of the top five cloud security risks, drawing insights and data from its own platform and third parties.

The five key risk areas are misconfigurations, external-facing vulnerabilities, weaponized vulnerabilities, malware inside a cloud environment, and remediation lag (that is, delays in patching).

The 2023 Qualys Cloud Security Insights report (PDF) provides more details on these risk areas. It will surprise no-one that misconfiguration is the first. As long ago as January 2020, the NSA warned that misconfiguration is a primary risk area for cloud assets – and little seems to have changed. Both Qualys and the NSA cite misunderstanding or avoidance of the concept of shared responsibility between cloud service providers (CSP) and cloud consumers is a primary cause of misconfiguration.

“Under the shared responsibility model,” explains Utpal Bhatt, CMO at Tigera, “CSPs are responsible for monitoring and responding to threats to the cloud and infrastructure, including servers and connections. They are also expected to provide customers with the capabilities needed to secure their workloads and data. The organization using the cloud is responsible for the protection of workloads running in the cloud. Workload protection includes secure workload posture, runtime protection, threat detection, incident response and risk mitigation.”

While CSPs provide security settings, the speed and simplicity of deploying data to the cloud often lead to these controls being ignored, while compensating consumer controls are inadequate. Misunderstanding or misusing the delineation of shared responsibility leaves cracks in the defense; and Qualys notes “these security ‘cracks’ can quickly open a cloud environment and expose sensitive data and resources to attackers.”

Qualys finds that misconfiguration (measured against the CIS benchmarks) is present in 60% of Google Cloud Platform (GCP) usage, 57% of Azure, and 34% of Amazon Web Services (AWS).

Travis Smith, VP of the Qualys threat research unit, suggests, “The reason AWS configurations are more secure than their counterparts at Azure and GCP can likely be attributed to the larger market share… there is more material on securing AWS compared to other CSPs in the market.”

Advertisement. Scroll to continue reading.

The report urges greater use of the Center for Internet Security (CIS) benchmarks to harden cloud environments. “No organization will deploy 100% coverage,” adds Smith, “but the [CIS benchmarks mapped to the MITRE ATT&CK tactics and techniques] should be strongly considered as a baseline if organizations want to reduce the risk of experiencing a security incident in their cloud deployments.”

The second big risk comes from external facing assets that contain a known vulnerability. Cloud assets with a public IP can be scanned by attackers looking for vulnerabilities. Log4Shell, an external facing vulnerability, is used as an example. “Today, patches exist for Log4Shell and its known secondary vulnerabilities,” says Qualys. “But Log4Shell is still woefully under remediated with 68.44% of detections being unpatched on external-facing cloud assets.”

Log4Shell also illustrates the third risk: weaponized vulnerabilities. “The existence of weaponized vulnerabilities is like handing anyone a key to your cloud,” says the report. Log4Shell allows attackers to execute arbitrary Java code or leak sensitive information by manipulating specific string substitution expressions when logging a string. It is easy to exploit and ubiquitous across clouds.

“Log4Shell was first detected in December 2021 and continues to plague enterprises globally. We have detected one million Log4Shell vulnerabilities, with a mere 30% successfully fixed. Due to complexity, remediating Log4Shell vulnerabilities takes, on average, 136.36 days (about four and a half months).”

The fourth risk is the presence of malware already in your cloud. While this doesn’t automatically imply ‘game over’, it will be soon if nothing is done. “The two greatest threats to cloud assets are cryptomining and malware; both are designed to provide a foothold in your environment or facilitate lateral movement,” says the report. “The key damage caused by cryptomining is based on wasted cost of compute cycles.”

While this may be true for miners, it is worth remembering that the miners found a way in. Given the efficiency of information sharing in the dark web, that route is likely to become known to other criminals. In August 2022, Sophos reported on ‘multiple adversary’ attacks, with miners often leading the charge. “Cryptominers,” Sophos told SecurityWeek at the time, “should be considered as the canary in the coal mine – an initial indicator of almost inevitable further attacks.”

In short, if you find a cryptominer in your cloud, start looking for additional malware, and find and fix the miner’s route in.

The fifth risk is slow vulnerability remediation – that is, an overlong patch timeframe. We have already seen that Log4Shell has a remediation time of more than 136 days, if it is done at all. The same general principle will apply to other patchable vulnerabilities.

Effective patching quickly lowers the quantity of vulnerabilities in your system and improves your security. Statistics show that this is more effectively performed by some automated method. “In almost every instance,” says the report, “automated patching proves to be a more effective remediation path than hoping manual efforts will effectively deploy critical patches and keep your business safer.”

For non-Windows systems, the effect of automated patching is an 8% improvement in the patch rate, and a two-day reduction in the time to remediate.

Related to the remediation risk is the concept of technical debt – the continued use of end-of-support (EOS) or end-of-life (EOL) products. These products are no longer supported by the supplier – there will be no patches to implement, and future vulnerabilities will automatically become zero day threats unless you can otherwise remediate. 

“More than 60 million applications discovered during our investigation are end-of-support (EOS) and end-of-life (EOL),” notes the report. Furthermore, “During the next 12 months, more than 35,000 applications will go end-of-support.”

Each of these risks need to be prioritized by defense teams. The speed of cloud use by consumers and abuse by attackers suggests that wherever possible defenders should employ automation and artificial intelligence to protect their cloud assets. “Automation is central to cloud security,” comments Bhatt, “because in the cloud, computing resources are numerous and in constant flux.”

Related: Google Cloud Now Offering $1 Million Cryptomining Protection

Related: Survey Shows Reasons for Cloud Misconfigurations are Many and Complex

Related: Qualys Flags Gaping Security Holes in Exim Mail Server

Related: Most Weaponized Vulnerabilities of 2022 and 5 Key Risks: Report

https://www.securityweek.com/these-are-the-top-five-cloud-security-risks-qualys-says/




Google Awards Over $60,000 for V8 Vulnerabilities Patched With Chrome 115 Update

Google on Wednesday announced a Chrome 115 update that patches 17 vulnerabilities, including 11 flaws reported by external researchers.

The browser update resolves three high-severity type confusion bugs in the V8 JavaScript and WebAssembly engine that earned the reporting researchers over $60,000 in bug bounties, Google notes in its advisory.

The internet giant says it handed out $43,000 in rewards to a security researcher named ‘Jerry’, who reported two of these V8 issues, tracked as CVE-2023-4068 and CVE-2023-4070.

A $21,000 bug bounty was awarded to Man Yue Mo of GitHub Security Lab, for reporting the third type confusion bug, tracked as CVE-2023-4069.

The latest Chrome update resolves six other high-severity vulnerabilities. Based on the paid bug bounties, the most severe of these is CVE-2023-4071, a heap buffer overflow bug in Visuals.

Next in line is an out-of-bounds read and write issue in WebGL (CVE-2023-4072), followed by an out-of-bounds memory access flaw in the ANGLE graphics engine abstraction layer (CVE-2023-4073).

The remaining three high-severity security defects that were externally reported are use-after-free vulnerabilities in Blink Task Scheduling, Cast, and WebRTC.

Advertisement. Scroll to continue reading.

The latest Chrome iteration also resolves two medium-severity bugs in Extensions: an insufficient data validation and an inappropriate implementation issue.

Google says it handed out a total of $123,000 in bug bounty rewards to the reporting researchers.

The latest Chrome release is currently rolling out as version 115.0.5790.170 for Mac and Linux and as versions 115.0.5790.170/.171 for Windows.

Google makes no mention of any of these vulnerabilities being exploited in attacks.

Related: Chrome 115 Patches 20 Vulnerabilities

Related: Chrome and Its Vulnerabilities – Is the Web Browser Safe to Use?

Related: Chrome 114 Update Patches Critical Vulnerability

https://www.securityweek.com/google-awards-60000-for-v8-vulnerabilities-patched-with-chrome-115-update/




Firefox 116 Patches High-Severity Vulnerabilities

Mozilla on Tuesday announced the release of Firefox 116, Firefox ESR 115.1, and Firefox ESR 102.14, which include patches for multiple high-severity vulnerabilities.

The browser maker lists a total of 14 CVEs in its advisory, nine of which are rated ‘high severity’. Three of the CVEs refer to memory safety bugs in Firefox.

The first of the high-severity flaws, tracked as CVE-2023-4045, is described as a cross-origin restrictions bypass in Offscreen Canvas, which failed to properly track cross-origin tainting.

The issue can allow web pages to view images displayed in a page from a different site, Sophos notes in an analysis of the update. Browsers include a same-origin policy that prevents HTML and JavaScript code originating on a website from accessing content on other sites.

The second high-severity issue that Firefox 116 patches is CVE-2023-4046, which is described as the use of an incorrect value during WASM compilation.

“In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process,” Mozilla notes.

The browser update also resolves CVE-2023-4047, a permission request bypass via clickjacking. A page could trick users into clicking on a carefully placed item but instead register the input as a click on a security dialog that was not displayed to the user.

Advertisement. Scroll to continue reading.

“Potentially risky permissions, such as accessing your location, sending notifications, activating the microphone and so on, are not supposed to be granted until you’ve seen and acted on a clear warning from the browser itself,” Sophos notes.

The three other high-severity vulnerabilities that Firefox 116 resolves include CVE-2023-4048 (an out-of-bounds read flaw causing DOMParser to crash when deconstructing a crafted HTML file), CVE-2023-4049 (race conditions leading to potentially exploitable use-after-free vulnerabilities), and CVE-2023-4050 (stack buffer overflow in StorageManager potentially leading to a sandbox escape).

Tracked as CVE-2023-4056, CVE-2023-4057, and CVE-2023-4058, the memory safety bugs resolved in Firefox 116 could have led to arbitrary code execution.

Most of these high-severity issues, Mozilla says, also impact Firefox extended support and Thunderbird, and were addressed in Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14.

Mozilla makes no mention of any of these vulnerabilities being exploited in attacks.

Related: Firefox 115 Patches High-Severity Use-After-Free Vulnerabilities

Related: Mozilla Patches High-Severity Vulnerabilities With Release of Firefox 111

Related: Firefox Updates Patch 10 High-Severity Vulnerabilities

https://www.securityweek.com/firefox-116-patches-high-severity-vulnerabilities/




Hacker Conversations: Youssef Sammouda, Bug Bounty Hunter

Youssef Sammouda is a Tunisian security researcher who focuses on bug bounty programs. He describes himself as, “Vulnerability researcher with an attraction to web applications and the security vulnerabilities that affect them.” He achieved first place in Facebook’s whitehat program in 2021, 2020 and 2019.

SecurityWeek talked to Sammouda about using cybersecurity research and bug bounties as a way of life and source of income.

“For the last five years,” he said (that is, starting in his mid-to-late teens), “I have focused on performing vulnerability assessments on some of the world’s biggest companies, mainly Meta and Google, and entering hacking competitions. I also currently work as a security consultant to start-up companies.”

This journey started early in his life. He began programming when he was twelve years old – but with no employment available for someone not yet in his teens, “I followed a path of general hacking and penetration testing. It wasn’t easy to do this legally. There wasn’t the same attitude toward whitehat research as there is today.” And there were no bug bounty programs to formalize the legality.

Legal pressures are something all researchers must consider. While most accept that conditions have improved, problems still exist today. As an example, in October 2021, a journalist with the Post-Dispatch discovered that teachers’ social security numbers were embedded in plain text in the html source code of a Missouri state website. The journalist took the responsible route. He verified that a few of the numbers he found were genuine SSNs, and then alerted the state authorities.

Youssef Sammouda, cybersecurity researcher
Youssef Sammouda

But rather than a reward, as would happen in a bug bounty program, the state governor ordered an investigation by state troopers with a view to considering criminal charges (for hacking) against the journalist. In the end, no charges were raised because no hacking occurred. A key element for hacking is the avoidance or bypassing of authentication processes – but there were no authentication processes: the data was plainly visible within the HTML that could be viewed by anyone with a browser.

But the threat of legal action hung over the journalist for several months – and such threats can have a chilling effect on researchers.

To avoid any legal issues, Sammouda switched to Capture the Flag (CTF) competitions to hone his skills, and gained knowledge in web and mobile application security. As the years passed, he reached the point where he could choose between working freelance or joining a company as an application security engineer. During this same period, bug bounty programs emerged as a potential source of income for a researcher.

Advertisement. Scroll to continue reading.

“The desire to work for myself was stronger than the desire to work for a company,” he told SecurityWeek. “I felt that if I went to work for a company like Facebook, I would be tied to their infrastructure and be constrained by their approaches. I didn’t want that. I wanted something where I could always be learning something new with new technologies. As a researcher, I am effectively working for and with every company rather than just one.”

And thus, an independent bug bounty hunter was born.

The key to being a researcher, as we have discovered with other security researchers, is a deeply rooted curiosity. “It’s about curiosity, and a need to challenge both yourself and the programmers who developed the code,” he explained. Earning bounties comes second to the curiosity: bounty hunting is merely a method of earning a living while satisfying curiosity.

We have also learned from other researchers that the image of a solitary hacker in front of a computer in a darkened room gives the wrong impression. 

“The ability to spend long periods on your own to do the research is not a pre-requisite, but the work forces you to spend many hours at your computer, much of it solitary. Working alone is a result of choosing this work – you don’t choose the work because you want to be alone.” Working alone is often – not always, nor with all researchers – a side-effect of being a researcher, not a requirement to be a researcher.

Worthy of note, however, is that Sammouda does not consider a formal education to be important. He went to university, but dropped out – and considers that everything he has learned has been self-taught through reading, forums, practice and mentally analyzing published proof of concept exploits.

Sammouda is a successful bounty hunter. “With Meta and Google, I make around $400,000 per year,” he told SecurityWeek. In the last twelve months, it was closer to $900,000. Overall, he has found about 140 bugs so far – around 120 in Facebook and the remaining 20 in Google and a few other big-name companies. So, how does he do this? 

It’s largely about preparation and planning. The planning shows in a professional approach to his work. “How much money you make will depend on the quantity and quality of the bugs you find in any year. But you can find in the program policy page how much is paid for a certain bug; and you can plan your year with an estimated value of how much you’ll make during the year.” He takes note of cashflow planning.

The preparation comes from the years he spent learning his trade since he began programming at twelve years old and taking part in Capture the Flag competitions. Now he is confident he will find a bug whenever he starts looking. 

“Although many people want to start on a bug bounty program, they don’t have the skillsets to do it the right way to efficiently to find the bugs. Before I started bug bounty hunting, I already had a very good background in security. That helped me start to make money right from the beginning. But the problem for many newcomers today is they’re not willing to spend enough time learning before they start hunting.”

He treats it with the discipline of working for a company without actually working for a company. It’s a bit like hanging wallpaper – the real trick is in preparing the wall before you start hanging the paper.

Get it right, and the bounty hunter earns both money and satisfaction. “Many of the bugs I found in Facebook were critical. I like all of them, but I mainly focus on bugs that would allow me to take over a Facebook account; for example, take over an Instagram account. By takeover, I mean gain access to someone’s account or get someone to visit a malicious website and get control of the account – so I like what I’ve done in finding these bugs. Two years ago, I focused on finding logic bugs in Facebook. I also found – and got $81,000 for it – a bug that allowed me to gain access to the entire Facebook infrastructure.

Most researchers are at least aware of the potential to sell discovered vulnerabilities to criminals on the dark web. Sammouda has a strong ethical code and has never been personally tempted. “In the past, hackers had to be black hats because this was the only way to make money from their skills,” he explained. “But nowadays I don’t think it is necessary. With things like bug bounty hunting and similar programs, you can make millions legally – so it doesn’t make sense to be a black hat.”

Apart from logic, this is down to his personal moral code. “For me,” he continued, “apart from the bounties, I feel I need to protect the users. With my skillsets I feel obliged to help protect the online users.”

There have been some suggestions that geopolitics can play a part in the difference between being a black hat and a white hat; that is, in some geographical locations it may be more difficult to make an honest profit from research. “I live in Tunisia,” he responded, “and I’ve never felt it is impossible to do bug bounties from anywhere in the world. Firstly, it’s online work; secondly the rewards are reasonable, and you can get paid in cryptocurrency. So, you can do bug bounties from anywhere in the world. It’s true that some researchers may prefer to work for their government in some areas, but there is always the choice to do the right thing.”

Being ignored by bounty schemes is sometimes raised as a potential reason for selling a vulnerability on the dark web. Sammouda doesn’t accept this. “To be honest, that has never happened to me. Companies that have a bug bounty program don’t ignore critical bugs.”

But what if…? “Following that hypothesis, I would use responsible disclosure.” Even if responsible disclosure has no effect, he wouldn’t switch to full disclosure – and in fact there have been examples. “I’ve had this experience,” he said. “One company didn’t want to fix the bugs; so, I had to contact a third-party company that worked with this company and say that if you don’t make them fix this bug it will affect you too. Eventually, the company was contacted by the third-party, and they fixed it. In another example, I had to contact the developers of an application directly because the company didn’t want to fix the bug.”

So, how do you become a successful bounty hunter like Youssef Sammouda? “First learn programming,” he says, “because cybersecurity research is about finding and understanding how a program works. If you’re not a programmer, you can’t even see the problem.” 

If you’re interested in web application security, you should learn the languages used. “The same logic applies for mobile, and other areas. From then on, you should spend a lot of time doing the research part. This can initially be done by playing Capture the Flag (CTF). You should do CTF for at least three years, playing two or three times every week. This will give you the experience to start your own hunting. And, of course, you must continually read the news, and new security research and whitepapers. But if you have the basic inherent curiosity, this will all come naturally.”

The real incentive for wannabe bounty hunters? It’s not even a full-time job. “It’s part time,” said the man earning $400,000 per year. “I’m not a full-time bounty hunter.”

Related: Hacker Conversations: Inside the Mind of Daniel Kelley, ex-Blackhat

Related: Cloudflare Launches Public Bug Bounty Program

Related: Salesforce Paid Out $12.2 Million in Bug Bounty Rewards to Date

https://www.securityweek.com/hacker-conversations-youssef-sammouda-bug-bounty-hunter/




Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks

Ivanti has warned customers about a second zero-day vulnerability in its Endpoint Manager Mobile (EPMM) product that has been exploited in targeted attacks.

Norwegian authorities announced on July 24 that a dozen government ministries had been targeted in a cyberattack involving exploitation of CVE-2023-35078, an Ivanti EPMM zero-day that allows an unauthenticated attacker to obtain sensitive information and make changes to impacted servers. 

Further investigation by cybersecurity firm Mnemonic revealed the existence of CVE-2023-3508, a high-severity flaw that allows an authenticated attacker with administrator privileges to remotely write arbitrary files to the server. 

Late last week, Ivanti published an advisory and CISA issued an alert to inform organizations about this second vulnerability and warn them of active exploitation. Organizations have been urged to immediately patch their devices.

EPMM, formerly known as MobileIron Core, is a mobile management software engine used by IT teams to set policies for mobile devices, applications, and content. 

Ivanti noted that CVE-2023-35081 can be exploited in conjunction with CVE-2023-35078 to bypass admin authentication and access control list (ACL) restrictions. 

“Successful exploitation can be used to write malicious files to the appliance, ultimately allowing a malicious actor to execute OS commands on the appliance as the tomcat user,” Ivanti explained. “As of now we are only aware of the same limited number of customers impacted by CVE-2023-35078 as being impacted by CVE-2023-35081.”

Advertisement. Scroll to continue reading.

It’s still unclear who is behind the attacks exploiting these zero-days, but it’s likely a state-sponsored threat actor.

While currently the vulnerabilities have been leveraged in limited attacks, exploitation is likely to increase considering that there are thousands of potentially vulnerable internet-exposed systems and proof-of-concept (PoC) code for CVE-2023-35078 has become available. 

CISA’s Known Exploited Vulnerabilities Catalog currently lists 10 Ivanti product flaws, but it does not include the latest zero-day. The flaws affect Pulse Connect Secure and MobileIron products, which Ivanti acquired in 2020.  

Related: Citrix Zero-Day Exploited Against Critical Infrastructure Organization

Related: Adobe Releases New Patches for Exploited ColdFusion Vulnerabilities

Related: Zero-Day Vulnerability Exploited to Hack Barracuda Email Security Gateway Appliances

https://www.securityweek.com/second-ivanti-epmm-zero-day-vulnerability-exploited-in-targeted-attacks/




US, Australia Issue Warning Over Access Control Vulnerabilities in Web Applications

New guidance from the Australian Cyber Security Centre (ACSC), the US Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) warns developers, vendors, and organizations of access control vulnerabilities in web applications.

Described as insecure direct object reference (IDOR) issues, they allow threat actors to read or tamper with sensitive data via application programming interface (API) requests that include the identifier of a valid user.

These requests are successful because the authentication or authorization of the user submitting the request is not properly validated, the three agencies explain.

IDOR vulnerabilities, the guidance notes, allow users to access data they should not be able to access either on the same privilege level or at a higher privilege level, to modify or delete data they should not be able to, or to access a function they should not be able to.

The flaws can be triggered by modifying the HTML form field data in the body of a POST request, by modifying identifiers in URLs or cookies to the identifiers of other users, or by intercepting and modifying legitimate requests using web proxies.

“These vulnerabilities are frequently exploited by malicious actors in data breach incidents because they are common, hard to prevent outside the development process, and can be abused at scale. IDOR vulnerabilities have resulted in the compromise of personal, financial, and health information of millions of users and consumers,” ACSC, CISA, and NSA say.

To prevent the prevalence of access control flaws and secure sensitive data, the vendors, designers, and developers of web applications are advised to implement secure-by-design and secure-by-default principles, ensuring that each request to access or modify data is properly authenticated and authorized.

Advertisement. Scroll to continue reading.

They can use automated tools to identify and address IDOR vulnerabilities, can rely on indirect reference maps to prevent exposure of IDs, names, and keys in URLs, and should vet all third-party libraries and frameworks they include in their applications.

End-user organizations, including those offering software-as-a-service (SaaS), should also vet the web applications they select, should follow best practices for supply chain risk management, and should apply available patches in a timely manner.

Organizations deploying on-premises software, private cloud, or infrastructure-as-a-service (IaaS) are advised to assess the available authentication and authorization checks in web applications and to perform regular vulnerability scanning and penetration testing to secure internet-facing assets.

Related: NSA, CISA Issue Guidance on 5G Network Slicing Security

Related: CISA, NSA Share Guidance on Securing CI/CD Environments

Related: CISA, NSA Share Guidance on Hardening Baseboard Management Controllers

https://www.securityweek.com/us-australia-issue-warning-over-access-control-vulnerabilities-in-web-applications/




In Other News: Data Breach Cost Rises, Russia Targets Diplomats, Tracker Alerts in Android 

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:  

IBM says average cost of data breach reached $4.45 million

IBM has published its 2023 Cost of a Data Breach Report. The tech giant says the global average cost of a data breach reached a record $4.45 million in 2023, with detection and escalation costs increasing 42% over the past three years.

CISA releases Risk and Vulnerability Assessment report for 2022

Advertisement. Scroll to continue reading.

CISA has released its Risk and Vulnerability Assessment report for fiscal year 2022 (PDF), concluding that threat actors still often rely on phishing and default credentials to conduct successful cyberattacks. The data comes from assessments conducted by the agency at various government and critical infrastructure organizations. 

Vulnerability in D-Link Wi-Fi USB adapter 

Users have been informed that the software driver for the D-Link DWA-117 AC600 MU-MIMO Wi-Fi USB adapter is affected by a vulnerability that can be exploited for local privilege escalation. D-Link has released a patch that should address the flaw. 

Vulnerabilities found in the Ninja Forms WordPress plugin

WordPress security firm Patchstack warns that the Ninja Forms plugin, which has over 900,000 active installations, is affected by several vulnerabilities, including ones that can allow unauthenticated attackers to obtain sensitive information and achieve privilege escalation on a targeted WordPress website. 

Jenkins security updates

Developers of the popular open source automation server Jenkins have patched several vulnerabilities, including a high-severity XSS flaw that can allow an attacker to control build log contents. 

Russian hackers target diplomatic entities with GraphicalProton malware

Starting in January 2023, Russia-linked APT actor BlueBravo (also tracked as APT29 and Midnight Blizzard) has been observed using three new malware families in attacks targeting diplomatic and foreign policy institutions in Eastern Europe. Recorded Future provides a technical analysis (PDF) of the malware — called GraphicalNeutrino, QuarterRig, and GraphicalProton — and of the tactics, techniques, and procedures (TTPs) used in the observed attacks.

North Korean hackers compromise JumpCloud customer 

Mandiant has provided technical details on the compromise of a US-based software solutions provider as result of the recent JumpCloud cyberattack. Highly-targeted, the sophisticated attack led to the compromise of five JumpCloud customers. Mandiant attributes the attack to UNC4899, a North Korean threat actor focused on cryptocurrency theft.

Google rolls out unknown tracker alerts on Android

Google has started rolling out unknown tracker alerts on Android, a new way to protect users from unwanted Bluetooth tracking. Users will be notified when an unknown Bluetooth tracker separated from its owner is traveling with them and will have the option to learn more on the respective tracker. Users will also be able to manually scan their surroundings for trackers.

Adaptive Shield receives $10 million in funding

SaaS applications security provider Adaptive Shield has received $10 million in funding from Blackstone Innovations Investments, which brings the total investment in the company to $44 million. The new funding will help Adaptive Shield continue expansion and keep up with emerging threats. 

https://www.securityweek.com/in-other-news-data-breach-cost-rises-russia-targets-diplomats-tracker-alerts-in-android/




Zimbra Patches Exploited Zero-Day Vulnerability

Zimbra this week released patches for a cross-site scripting (XSS) vulnerability in Collaboration Suite that has been exploited in malicious attacks.

Tracked as CVE-2023-37580, the vulnerability was disclosed earlier this month, when Zimbra recommended manual patching for version 8.8.15 of the popular email and collaboration solution.

No CVE identifier had been issued for the flaw at the time, but Clement Lecigne from Google’s Threat Analysis Group (TAG) said that in-the-wild exploitation had been observed.

This week, Zimbra announced software updates for Zimbra Collaboration Suite versions 8.8.15, 9.0.0, and 10.0.x. A fix for the exploited security bug was included in version 8.8.15 patch 41 of the solution.

“A cross-site scripting (XSS) vulnerability that was present in the Zimbra Classic Web Client has been addressed,” Zimbra notes in its advisory.

The update resolves two other vulnerabilities in the suite, namely CVE-2023-38750, an issue leading to the exposure of internal JSP and XML files, and CVE-2023-0464, a bug “related to the verification of X.509 certificate chains that include policy constraints” in OpenSSL.

Patches for the last two flaws were included in the Zimbra Collaboration Suite versions 10.0.2 and 9.0.0 patch 34 as well. CVE-2023-37580, however, only impacts version 8.8.15 of the solution.

Advertisement. Scroll to continue reading.

Additional information on the software updates can be found on Zimbra’s security center webpage.

On Thursday, the US Cybersecurity and Infrastructure Security Agency (CISA) announced that it has added CVE-2023-37580 to its Known Exploited Vulnerabilities Catalog.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA notes.

Per Binding Operational Directive (BOD) 22-01, federal agencies are required to identify vulnerabilities added to CISA’s ‘Must Patch’ list and apply the available fixes within three weeks. In this case, patches should be applied by August 17, 2023.

Related: Zimbra Flaw Exploited by Russia Added to CISA ‘Must Patch’ List

Related: Zimbra Patches Under-Attack Code Execution Bug

Related: Critical Zimbra RCE Vulnerability Exploited in Attacks

https://www.securityweek.com/zimbra-patches-exploited-zero-day-vulnerability/