Juniper Networks Kicks Off 2023 With Patches for Over 200 Vulnerabilities

The first round of security advisories published by Juniper Networks for 2023 cover hundreds of vulnerabilities that have been patched in the networking giant’s products.

The 32 Juniper Networks security advisories published by the company this week cover more than 230 vulnerabilities, roughly 200 of which impact third-party components.

Three advisories have an overall severity rating of critical and they all describe vulnerabilities affecting third-party components. Twenty advisories have a ‘high severity’ rating and nine have a ‘medium severity’ rating.

Roughly two dozen Junos OS vulnerabilities have been patched by the company. All of them can be leveraged for denial-of-service (DoS) attacks, and a majority can be exploited by unauthenticated attackers who have network access to the targeted device.

There is no indication that any of these vulnerabilities has been exploited in the wild.

The US Cybersecurity and Infrastructure Security Agency (CISA) has advised organizations to review Juniper’s advisories and take action as necessary.

Related: ​​U.S. Officials Ask Juniper Networks About Investigation Into 2015 Backdoor

Related: Juniper Patches Critical Third-Party Flaws Across Product Portfolio

Related: Juniper Networks Patches Critical Vulnerabilities in Firewalls

Related: Juniper Networks Patches Vulnerabilities in Contrail Networking, Junos OS

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

https://www.securityweek.com/juniper-networks-kicks-2023-patches-over-200-vulnerabilities




Fortinet Says Recently Patched Vulnerability Exploited to Hack Governments

Fortinet reported this week that a recently patched vulnerability tracked as CVE-2022-42475 has been exploited in highly targeted attacks aimed at government organizations.

The security hole impacts the FortiOS SSL-VPN and it can allow a remote, unauthenticated hacker to execute arbitrary code or commands using specially crafted requests.

The vulnerability’s existence was disclosed on December 12, 2022, when Fortinet warned that it was aware of in-the-wild exploitation. The company at the time announced patches and shared indicators of compromise (IoCs).

In a blog post published this week, Fortinet’s Product Security Incident Response Team (PSIRT) shared additional details, including on the malware sample delivered in the observed attacks, as well as the related network traffic.

“The complexity of the exploit suggests an advanced actor and that it is highly targeted at governmental or government-related targets,” the cybersecurity firm said.

When the existence of CVE-2022-42475 came to light, researcher Kevin Beaumont said that it appeared to have been exploited by a ransomware group, but after additional information emerged, the expert said it may have actually been a state-sponsored threat actor disguising its activities as a ransomware operation.

According to new information shared by Fortinet, the hackers delivered a variant of a generic Linux malware customized for targeting its FortiOS operating system.

While some of the payloads could not be recovered, the company’s analysis indicated that the attackers were trying to execute commands, download additional malicious components to compromised systems, and manipulate FortiOS logging functionality.

Regarding the logs, the malware deployed in the attack attempted to patch the FortiOS logging process in an effort to alter logs and evade detection. The malware is also capable of killing the logging process.

This detailed analysis has allowed Fortinet to share additional IoCs.

It’s not uncommon for malicious actors to exploit vulnerabilities in Fortinet products in their attacks, and the vendor admitted in the past that some customers are slow when it comes to patching, even actively exploited vulnerabilities.

According to data from CISA’s Known Exploited Vulnerabilities Catalog, a total of nine Fortinet product vulnerabilities have been exploited in attacks since 2018.

Related: PoC Published for Fortinet Vulnerability as Mass Exploitation Attempts Begin

Related: Cybercriminals Selling Access to Networks Compromised via Recent Fortinet Vulnerability

Related: High-Severity Command Injection Flaws Found in Fortinet’s FortiTester, FortiADC

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

https://www.securityweek.com/fortinet-says-recently-patched-vulnerability-exploited-hack-governments




Vulnerability with 9.8 severity in Control Web Panel is under active exploit

Photograph depicts a security scanner extracting virus from a string of binary code. Hand with the word "exploit"
Getty Images

Malicious hackers have begun exploiting a critical vulnerability in unpatched versions of the Control Web Panel, a widely used interface for web hosting.

“This is an unauthenticated RCE,” members of the Shadowserver group wrote on Twitter, using the abbreviation for remote code exploit. “Exploitation is trivial and a PoC published.” PoC refers to a proof-of-concept code that exploits the vulnerability.

The vulnerability is tracked as CVE-2022-44877. It was discovered by Numan Türle of Gais Cyber Security and patched in October in version 0.9.8.1147. Advisories didn’t go public until earlier this month, however, making it likely some users still aren’t aware of the threat.

Figures provided by Security firm GreyNoise show that attacks began on January 7 and have slowly ticked up since then, with the most recent round continuing through Wednesday. The company said the exploits are coming from four separate IP addresses located in the US, Netherlands, and Thailand.

Shadowserver shows that there are roughly 38,000 IP addresses running Control Web Panel, with the highest concentration in Europe, followed by North America and Asia.

The severity rating for CVE-2022-44877 is 9.8 out of a possible 10. “Bash commands can be run because double quotes are used to log incorrect entries to the system,” the advisory for the vulnerability stated. As a result, unauthenticated hackers can execute malicious commands during the login process. The following video demonstrates the flow of the exploit.

[embedded content]
Centos Web Panel 7 Unauthenticated Remote Code Execution – CVE-2022-44877

The vulnerability resides in the /login/index.php component and resulted from CWP using a faulty structure when logging incorrect entries, according to the Daily Swig. The structure is: echo "incorrect entry, IP address, HTTP_REQUEST_URI" >> /blabla/wrong.log. “Since the request URI comes from the user, and as you can see it is within double quotes, it is possible to run commands such as $(blabla), which is a bash feature,” Türle told the publication.

Given the ease and severity of exploitation and the availability of working exploit code, organizations using Control Web Panel should ensure they’re running version 0.9.8.1147 or higher.

https://arstechnica.com/?p=1909755




Tesla Returns as Pwn2Own Hacker Takeover Target

Electric car maker Tesla is using the annual Pwn2Own hacker contest to incentivize security researchers to showcase complex exploit chains that can lead to complete vehicle compromise.

Tesla, in tandem with Pwn2Own organizations Zero Day Initiative, is offering a $600,000 cash prize to any hacker capable of writing exploits that pivot through multiple systems in the car to gain arbitrary code execution.

“Success here gets a big payout and, of course, a brand-new Tesla,” contest organizers announced Thursday.

This isn’t the first time Tesla has sought to attract the attention of advanced exploit writers at Pwn2Own. Back in 2019, the company gave away a Tesla Model 3 to a pair of researchers demonstrating successful exploits and this year the organizers plan to raise the level of complexity of what constitutes a successful car-hacking exploit.

Hackers can register an entry against either a Tesla Model 3 (Intel or Ryzen-based) or the Tesla Model S (Ryzen-based).

This year, the organizers are looking for exploits targeting Tesla’s Tuner, Wi-Fi, Bluetooth or Modem components.  Hackers must demonstrate a successful intermediate pivot to the vehicle’s infotainment system and execute code against VCSEC, Gateway or Autopilot.

In addition to the vehicle itself and $500,000, contestants can go for the additional options to raise the payout to $600,000. “This represents the single largest target in Pwn2Own history,” conference organizers said in a note posted Thursday.

Organizers believe a complete vehicle takeover exploit is a tough undertaking. “It’s difficult to express the complexity of completing such a demonstration, but we’re certainly hopeful that someone can show off their exploit skills and drive off a winner.”

Pwn2Own is also offering cash prizes ranging from $250,000 to $400,000 to entice attackers to showcase exploits pivoting through some of the vehicle’s sub-systems. “This level requires the contestant to get arbitrary code execution on two different sub-systems in the vehicle, which is certainly a difficult challenge.”

Pwn2Own also announced the addition of a Steam VM Escape category with both a Tesla Model 3 and a Tesla Model S available as targets.

The annual hacker contest will also offer prizes for exploits for VMWare virtual machine escapes, attacks against Microsoft DNS Server and ISC BIND, and exploits for enterprise collaboration tools Zoom and Microsoft Teams.

Related: Pwn2Own 2019: Researchers Win Tesla After Hacking Its Browser 

Related: $200,000 Awarded for Zoom Zero-Click Zoom Exploit at Pwn2Own

Related: Over $1.1 Million Awarded at Pwn2Own 2022 for 25 Zero-Day Vulns

Related: ICS Exploits Earn Hackers $400,000 at Pwn2Own Miami 2022

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series.
Ryan is a veteran cybersecurity strategist who has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s past career as a security journalist included bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

https://www.securityweek.com/tesla-returns-pwn2own-hacker-takeover-target




Fortinet says hackers exploited critical vulnerability to infect VPN customers

A cake made to resemble FortiGate hardware.

An unknown threat actor abused a critical vulnerability in Fortinet’s FortiOS SSL-VPN to infect government and government-related organizations with advanced custom-made malware, the company said in an autopsy report on Wednesday.

Tracked as ​​CVE-2022-42475, the vulnerability is a heap-based buffer overflow that allows hackers to remotely execute malicious code. It carries a severity rating of 9.8 out of a possible 10. A maker of network security software, Fortinet fixed the vulnerability in version 7.2.3 released on November 28 but failed to make any mention of the threat in the release notes it published at the time.

Mum’s the word

Fortinet didn’t disclose the vulnerability until December 12, when it warned that the vulnerability was under active exploit against at least one of its customers. The company urged customers to ensure they were running the patched version of the software and to search their networks for signs the vulnerability had been exploited on their networks. FortiOS SSL-VPNs are used mainly in border firewalls, which cordon off sensitive internal networks from the public Internet.

On Wednesday, Fortinet provided a more detailed account of the exploit activity and the threat actor behind it. The post, however, provided no explanation for the failure to disclose the vulnerability when it was fixed in November. A company spokesperson declined to answer questions sent by email about the failure or what the company’s policy is for disclosure of vulnerabilities.

“The complexity of the exploit suggests an advanced actor and that it is highly targeted at governmental or government-related targets,” Fortinet officials wrote in Wednesday’s update. They continued:

  • The exploit requires a deep understanding of FortiOS and the underlying hardware.
  • The use of custom implants shows that the actor has advanced capabilities, including reverse-engineering various parts of FortiOS.
  • The actor is highly targeted, with some hints of preferred governmental or government-related targets.
  • The discovered Windows sample attributed to the attacker displayed artifacts of having been compiled on a machine in the UTC+8 timezone, which includes Australia, China, Russia, Singapore, and other Eastern Asian countries.
  • The self-signed certificates created by the attackers were all created between 3 and 8 am UTC. However, it is difficult to draw any conclusions from this given hackers do not necessarily operate during office hours and will often operate during victim office hours to help obfuscate their activity with general network traffic.

An analysis Fortinet performed on one of the infected servers showed that the threat actor used the vulnerability to install a variant of a known Linux-based implant that had been customized to run on top of the FortiOS. To remain undetected, the post-exploit malware disabled certain logging events once it was installed. The implant was installed in /data/lib/libips.bak path. The file may be masquerading as part of Fortinet’s IPS Engine, located at /data/lib/libips.so. The file /data/lib/libips.so was also present but had a file size of zero.

After emulating the implant’s execution, Fortinet researchers discovered a unique string of bytes in its communication with command-and-control servers that can be used for a signature in intrusion-prevention systems. The buffer “\x00\x0C\x08http/1.1\x02h2\x00\x00\x00\x14\x00\x12\x00\x00\x0Fwww.example.com” (unescaped) will appear inside the “Client Hello” packet.

Other signs a server has been targeted include connections to a variety of IP addresses, including 103[.]131[.]189[.]143, and the following TCP sessions:

  • Connections to the FortiGate on port 443
  • Get request for /remote/login/lang=en
  • Post request to remote/error
  • Get request to payloads
  • Connection to execute command on the FortiGate
  • Interactive shell session.

The autopsy includes a variety of other indicators of compromise. Organizations that use the FortiOS SSL-VPN should read it carefully and inspect their networks for any signs they’ve been targeted or infected.

As noted earlier, the autopsy fails to explain why Fortinet didn’t disclose CVE-2022-42475 until after it was under active exploit. The failure is particularly acute given the severity of the vulnerability. Disclosures are crucial because they help users prioritize the installation of patches. When a new version fixes minor bugs, many organizations often wait to install it. When it fixes a vulnerability with a 9.8 severity rating, they’re much more likely to expedite the update process.

In lieu of answering questions about the lack of disclosure, Fortinet officials provided the following statement:

We are committed to the security of our customers. In December 2022, Fortinet distributed a PSIRT advisory (FG-IR-22-398) that detailed mitigation guidance and recommended next steps regarding CVE-2022-42475. We notified customers via the PSIRT Advisory process and advised them to follow the guidance provided and, as part of our ongoing commitment to the security of our customers, continue to monitor the situation. Today, we shared additional extended research regarding CVE-2022-42475. For more information, please visit the blog.

The company said additional malicious payloads used in the attacks couldn’t be retrieved.

https://arstechnica.com/?p=1909594




Twitter Finds No Evidence of Vulnerability Exploitation in Recent Data Leaks

Twitter says it has analyzed the recently advertised databases allegedly containing the information of hundreds of millions of its users and found no evidence that a vulnerability has been exploited.

In August 2022, Twitter informed customers that a vulnerability in its systems had been exploited to obtain user data. The flaw, patched in January 2022, was used to determine whether a specified phone number or email address were tied to an existing Twitter account.

Twitter confirmed exploitation of the vulnerability after reports started circulating that the flaw had been leveraged to collect data on 5.4 million users.

A few months later, a cybersecurity expert said he had obtained a database that appeared to show the Twitter data breach was far bigger than initially reported, with tens of millions of impacted accounts.

Twitter said the data was the same in both cases, but it never clarified exactly how many users are believed to be impacted.

In December, just before Christmas, someone offered to sell a database of 400 million Twitter user records allegedly obtained through the exploitation of the same flaw.

A few weeks later, in early January, an individual leaked a database containing the information of roughly 235 million Twitter users, including name, username, email addresses, follower count, and account creation date. Experts who analyzed the publicly available data said it likely came from web scraping.

Twitter confirmed on Wednesday that the 200 million records were not obtained through the exploitation of the vulnerability patched in January 2022, nor other weaknesses in its systems.

In addition, the social media giant clarified that the 200 million records actually appear to be the same dataset as the previously sold 400 million records, but with duplicate entries removed.

The company also clarified that none of the leaked databases contained any passwords or other information that could lead to passwords getting compromised.

“Based on information and intel analyzed to investigate the issue, there is no evidence that the data being sold online was obtained by exploiting a vulnerability of Twitter systems. The data is likely a collection of data already publicly available online through different sources,” Twitter said.

Ireland’s Data Protection Commission (DPC) announced in December that it had launched an investigation in response to the data leak reports involving 5.4 million Twitter users.

In the statement published this week, Twitter said, “We are in contact with Data Protection Authorities and other relevant regulators from different countries to provide clarification about the alleged incidents, and we will continue to do so.”

Just like Facebook, Twitter has its European headquarters in Ireland. Facebook and Instagram have been issued hundreds of millions of euros in fines in the past year in Ireland over data privacy violations.

The individual offering to sell the 400 million records was actually hoping that the massive fines issued to other social media companies would convince Twitter to buy the data itself to prevent it from getting leaked.

Related: Twitter Logs Out Some Users Due to Security Issue Related to Password Resets

Related: Twitter Security Chief Resigns as Musk Sparks ‘Deep Concern’

Related: Twitter Ex-Security Chief Tells US Congress of Security Concerns

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

https://www.securityweek.com/twitter-finds-no-evidence-vulnerability-exploitation-recent-data-leaks




Cisco Warns of Critical Vulnerability in EoL Small Business Routers

Cisco this week announced that no patches will be released for a critical-severity vulnerability impacting small business RV016, RV042, RV042G, and RV082 routers, which have reached end of life (EoL).

Tracked as CVE-2023-20025 (CVSS score of 9.0), the security defect impacts the web-based management interface of the routers and could be exploited to bypass authentication.

The issue exists because user input within incoming HTTP packets is not properly validated, allowing an attacker to send crafted HTTP requests to the router, to bypass authentication and gain root access to the operating system.

“Cisco has not and will not release software updates that address this vulnerability. There are no workarounds that address this vulnerability,” Cisco notes in its advisory.

The tech giant also warned of a high-severity bug in the web-based management interface of the same routers, which could lead to remote command execution. Tracked as CVE-2023-20026, the vulnerability requires for the attacker to be authenticated.

To mitigate these vulnerabilities, administrators can disable remote management on the affected devices, and block access to ports 443 and 60443.

Cisco warns that proof-of-concept exploit code targeting this vulnerability is available publicly, but says it is not aware of malicious attacks exploiting the bug. However, it’s not uncommon for threat actors to target Cisco’s small business RV routers in their attacks.

This week Cisco also announced patches for high-severity vulnerabilities impacting IP Phone 7800 and 8800 series phones, Industrial Network Director (IND), and the BroadWorks Application Delivery and BroadWorks Xtended Services platforms.

The insufficient validation of user-supplied input on the web-based management interface of IP Phone 7800 and 8800 series phones could allow a remote attacker to bypass authentication.

The security issue in IND “exists because a static key value that is stored in the application can be used to encrypt application data and remote credentials” and can be exploited to decrypt data and access remote systems monitored by IND.

The BroadWorks platforms are impacted by an improper input validation bug allowing attackers to send crafted HTTP requests and trigger a denial-of-service (DoS) condition.

Cisco says it is not aware of any malicious attacks targeting the vulnerabilities. More information about the addressed bugs can be found on Cisco’s product security page.

Related: Cisco Secure Email Gateway Filters Bypassed Due to Malware Scanner Issue

Related: Cisco Patches High-Severity Bugs in Email, Identity, Web Security Products

Related: Cisco Confirms In-the-Wild Exploitation of Two VPN Vulnerabilities

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/cisco-warns-critical-vulnerability-eol-small-business-routers




Threema Under Fire After Downplaying Security Research

The developers of the open source secure messaging app Threema have come under fire over their public response to a security analysis conducted by researchers at the Swiss university ETH Zurich.

The Swiss company that makes Threema claims to have more than 10 million users and over 7,000 on-premises customers. Customers reportedly include the Swiss government and German chancellor Olaf Scholz.

ETH Zurich researchers analyzed the application and its communication protocol last year and discovered seven types of attacks that could be launched by an attacker who can intercept communications, one who has compromised a server, or one who has hacked the targeted user’s device.

According to the researchers, they found issues related to authentication and encryption that could allow an attacker to obtain message metadata (not actual conversations), prevent messages from being delivered, clone accounts, recover the private key associated with a user’s Threema ID, and encrypt potentially compromising messages and deliver them to a user in an effort to plant evidence.

The researchers published a paper detailing their findings and set up a dedicated website for their security analysis of Threema.

The findings were reported to Threema developers in October 2022 and the company has since released mitigations, as well as a new protocol, to mitigate the attack methods.

In a statement published on its website the day the researchers made their findings public, Threema thanked them, but noted that none of the attack methods they described “ever had any considerable real-world impact”.

The company pointed out that the attacks are not easy to pull off, requiring extended physical access to an unlocked device, extensive social engineering, or considerable computing resources.

“Most [attacks] assume extensive and unrealistic prerequisites that would have far greater consequences than the respective finding itself,” Threema said in a blog post.

The statement downplays the findings, but that is not uncommon for vendors. However, a message posted by Threema on Twitter led to the company being vastly criticized by the cybersecurity community.

“There’s a new paper on Threema’s old communication protocol. Apparently, today’s academia forces researchers and even students to hopelessly oversell their findings,” the company wrote in a message pointing to its official statement.

The company’s blog post on the matter was initially titled “New Paper on Old Threema Protocol”, but was later renamed to “Statement on ETH Findings”.

Kenneth Paterson, an ETH Zurich professor involved in the research, described the tweet as “unexpectedly dismissive”, claiming that the Threema protocol was updated thanks to their work.

Threema response to security research criticized

Threema, on the other hand, denies this and claims that the introduction of the new protocol “was planned for some time and coincided with the disclosure period of the researchers”.

Members of the cybersecurity community described the company’s response as aggressive, unprofessional, and arrogant. It seems that the vulnerabilities gained more attention due to Threema’s poor response rather than the actual severity of the flaws.

Threema response to security research criticized

Related: Google Rolls out E2EE For Android Messages App

Related: Encrypted Services Providers Concerned About EU Proposal for Encryption Backdoors

Related: Swiss Army Knifes WhatsApp at Work

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

https://www.securityweek.com/threema-under-fire-after-downplaying-security-research




How secure a Twitter replacement is Mastodon? Let us count the ways

How secure a Twitter replacement is Mastodon? Let us count the ways
Getty Images

As Elon Musk critics flee from Twitter, Mastodon seems to be the most common replacement. In the last month, the number of monthly active users on Mastodon has rocketed more than threefold, from about 1 million to 3.5 million, while total number of users jumped from about 6.5 million to 8.7 million.

This substantial increase raises important questions about the security of this new platform, and for good reason. Unlike the centralized model of Twitter and virtually every other social media platform, Mastodon is built on a federated model of independent servers, known as instances. In this respect, it’s more akin to email or Internet Relay Chat (IRC), where security depends on the ability and attention of the admin who configured it and maintains each individual server.

The past month has seen the number of instances mushroom from about 11,000 to more than 17,000. The people running these instances are volunteers who may or may not be versed in the nuances of security. The difficulty of configuring and maintaining instances leaves plenty of room for mistakes that can put user passwords, email addresses, and IP addresses at risk of being revealed (more about that later). Twitter security left much to be desired, but at least it had a dedicated staff with a deep background in security.

Security cons

“I honestly think that’s the biggest concern facing security in space,” Mike Lendvay, a certified information security professional and certified cloud security professional who also runs the Mastodon instance friendsofdesoto.social. “Especially with the Twitter diaspora, you’ve had a lot of servers go up very quickly, and there’s going to be a very uneven amount of skill level in the people administering them.”

Another concern is the software powering the Mastodon platform. It has never undergone a formal security audit, although the European Commission sponsored a bug bounty program that resulted in patches for 35 valid bug submissions. Earlier this month, a researcher discovered a misconfiguration in multiple instances that allowed for the downloading and deleting of all files stored on the server and replacing every user’s profile picture.

The lack of an audit and years of robust security testing by outsiders means that serious security weaknesses are almost surely present.

To that point, a separate researcher this month discovered a server that had somehow managed to scrape the data of more than 150,000 users from a misconfigured server. Fortunately, the data was limited to account names, display names, profile pictures, following count, follower count, and last status update. A third vulnerability discovered this month on one instance made it possible to steal users’ plaintext passwords by injecting specially crafted HTML into the site.

Of course, all platforms have these sorts of vulnerabilities, and Mastodon developers and instance admins have been quick to patch them once reported. But other platforms have teams of security engineers, researchers, and compliance specialists who pore over recently patched vulnerabilities to ensure their platform runs up-to-date components. Mastodon’s federated structure can’t replicate this. Expecting volunteers to perform at the same scale as a centralized platform is unrealistic, to say the least.

The lack of dedicated security teams might be a problem, particularly in the event of a high-security vulnerability in the software ecosystem Mastodon relies on. The platform is built on Ruby on Rails, Postgres, and Redis. On the one hand, the combination of these three open source apps is tried and true, with use by notable platforms including GitHub, GitLab, Shopify, and Discourse.

But things could go badly if one of those apps is hit by something with the severity of something like HeartBleed, the 2014 bug in the open source OpenSSL app that caused the disclosure of all kinds of sensitive data from banking websites and other high-value targets.

What’s more, Mastodon software has no auto-update or even update-availability feature.

“You have to check the GitHub releases, personally,” Lendvay said. “I try to do that weekly. But for many, I would imagine they would hear through the grapevine. I’ve seen disparate versions running, so who knows what the consistency will be.”

Mastodon—or at least instances hosting widely known or influential users—is also likely to be much more susceptible to distributed denial-of-service attacks (DDos), which knock sites offline by bombing servers with more traffic or commands than they can handle. Centralized platforms with deep pockets consider DDoS mitigation servers as a basic cost. Volunteer-run instances aren’t likely to have the same resources. If Mastodon’s user base continues its current growth spurt, this susceptibility will likely be used to silence critics of all stripes.

Besides stealing data, hackers might also be tempted to hack the accounts of influential people or take control of administrative functions. In either case, the hacker could go on to impersonate influential users.

“I would bet money there are vulns in the ActivityPub protocol that will allow someone to broadcast a false toot attributable to a famous handle,” one user said. “Or there will be some other protocol issue found.”

Lastly, Mastodon is likely more susceptible to harassment and misinformation campaigns, assuming they run at scale.

“On personal security, there aren’t a lot of protections against harassment,” said Jon Pincus of the Nexus of Privacy. “Many instances aren’t well-moderated (including mastodon.social, which [Mastodon creator] Eugen [Rochko] runs). Even well-moderated instances can be overwhelmed by determined attacks.”

https://arstechnica.com/?p=1900717




Patches for 6 zero-days under active exploit are now available from Microsoft

The phrase Zero Day can be spotted on a monochrome computer screen clogged with ones and zeros.

It’s the second Tuesday of the month, and that means it’s Update Tuesday, the monthly release of security patches available for nearly all software Microsoft supports. This time around, the software maker has fixed six zero-days under active exploit in the wild, along with a wide range of other vulnerabilities that pose a threat to end users.

Two of the zero-days are high-severity vulnerabilities in Exchange that, when used together, allow hackers to execute malicious code on servers. Tracked as CVE-2022-41040 and CVE-2022-41082, these vulnerabilities came to light in September. At the time, researchers in Vietnam reported they had been used to infect on-premises Exchange servers with web shells, the text-based interfaces that allow people to remotely execute commands.

Better known as ProxyNotShell, the vulnerabilities affect on-premises Exchange servers. Shodan searches at the time the zero-days became publicly known showed roughly 220,000 servers were vulnerable. Microsoft said in early October that it was aware of only a single threat actor exploiting the vulnerabilities and that the actor had targeted fewer than 10 organizations. The threat actor is fluent in Simplified Chinese, suggesting it has a nexus to China.

A third zero-day is CVE-2022-41128, a critical Windows vulnerability that also allows a threat actor to execute malicious code remotely. The vulnerability, which works when a vulnerable device accesses a malicious server, was discovered by Clément Lecigne of Google’s Threat Analysis Group. Because TAG tracks hacking backed by nation-states, the discovery likely means that government-backed hackers are behind the zero-day exploits.

Two more zero-days are escalation-of-privilege vulnerabilities, a class of vulnerability that, when paired with a separate vulnerability or used by someone who already has limited system privileges on a device, elevates system rights to those needed to install code, access passwords, and take control of a device. As security in applications and operating systems has improved in the past decade, so-called EoP vulnerabilities have grown in importance.

CVE-2022-41073 affects the Microsoft print spooler, while CVE-2022-41125 resides in the Windows CNG Key Isolation Service. Both EoP vulnerabilities were discovered by the Microsoft Security Threat Intelligence team.

The last zero-day fixed this month is also in Windows. CVE-2022-41091 allows hackers to create malicious files that evade Mark of the Web defenses, which are designed to work with security features such as Protected View in Microsoft Office. Will Dormann, a senior vulnerability analyst at security firm ANALYGENCE, discovered the bypass technique in July.

In all, this month’s Update Tuesday fixed a total of 68 vulnerabilities. Microsoft gave a “critical” severity rating to 11 of them, with the remainder carrying the rating “important.” Patches generally install automatically within about 24 hours. Those who want to install updates immediately can go to Windows > Settings > Updates and Security > Windows Update. Microsoft’s full rundown is here.

https://arstechnica.com/?p=1896179