Serious Vulnerabilities Found in CODESYS Software Used by Many ICS Products

Researchers have discovered 10 vulnerabilities — a majority rated critical or high severity — in CODESYS industrial automation software that is used in many industrial control system (ICS) products.

Researchers at Russian cybersecurity company Positive Technologies identified the vulnerabilities in various products made by CODESYS. They initially found the flaws in a programmable logic controller (PLC) made by WAGO, but further analysis showed that the issues were actually introduced by CODESYS software that is used by more than a dozen manufacturers for their PLCs, including Beckhoff, Kontron, Moeller, Festo, Mitsubishi, HollySys and several Russian firms.

Six of the vulnerabilities have been rated critical and they can be exploited using specially crafted requests for remote code execution or to crash the system. The three flaws rated high severity can be leveraged for DoS attacks or remote code execution using specially crafted requests.

The remaining security bug has been rated medium severity and it can be exploited to disrupt targeted systems.

Learn more about vulnerabilities in industrial systems at SecurityWeek’s ICS Cyber Security Conference and SecurityWeek’s Security Summits virtual event series

Some of the vulnerabilities can be exploited only by an authenticated attacker or if the controller is not protected by a password, but Positive Technologies says some of the weaknesses can be exploited simply by having network access to the targeted device.

“The vendor rated some of these vulnerabilities as 10 out of 10, or extremely dangerous,” explained Vladimir Nazarov, head of ICS security at Positive Technologies. “Their exploitation can lead to remote command execution on PLC, which may disrupt technological processes and cause industrial accidents and economic losses.”

CODESYS has released updates for its CODESYS V2 web server, Runtime Toolkit and PLCWinNT products to address the vulnerabilities. The vendor has published separate advisories for the critical-, high- and medium-severity issues, and advises customers to install the updates.

Positive Technologies was sanctioned recently by the U.S. government for allegedly supporting Kremlin intelligence agencies. However, the company said it will continue to responsibly disclose the vulnerabilities found by its employees in the products of major U.S. companies.

Related: VMware Patches Critical Flaw Reported by Sanctioned Russian Security Firm

Related: Hackers Can Exploit Siemens Control System Flaws in Attacks on Power Plants

Related: Many Vulnerabilities Discovered in Moxa Industrial Switches

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/WA0pCJtMkqs/serious-vulnerabilities-found-codesys-software-used-many-ics-products




Two Carbanak Gang Members Sentenced to 8 Years in Prison

Two members of the notorious Carbanak cybergang were sentenced to 8 years in prison, Kazakhstani authorities announced this week.

While they did not reveal the names of the sentenced individuals, the Kazakh authorities did say that they were accused of stealing roughly $4.7 million from two banks in the country between 2016 and 2017, as well as of attempting to steal $18.5 million more.

The stolen funds were transferred to 250 payment cards that were then distributed for cash out at ATMs across Europe, including in Belgium, the Czech Republic, Estonia, France, Germany, the Netherlands, Russia, Spain, and Switzerland.

“The rest of the members of this criminal organization have been identified and are on the international wanted list,” a translation of the sentencing announcement reads.

Tracked as Carbanak, Anunak and Cobalt, the gang evolved its malware and moved to more sophisticated attacks around 2016, employing a custom version of the Cobalt Strike pen testing tool.

[ READ: Historical Breadcrumbs Link Magecart 5 to Carbanak Group ]

Employing spear-phishing emails, the threat actors targeted bank employees with their malware, which provided them with access to a victim institution’s network, including the servers that controlled automated teller machines (ATMs).

Using this unauthorized access, the attackers would instruct ATMs to dispense cash at specific times, when money mules were present to collect the money. The hackers also transferred funds to bank accounts they controlled, and even modified account balances so they could withdraw large amounts of cash.

Working with the Russian and Moldovan mafia, the hackers often laundered the proceeds using Bitcoins. More than100 financial organizations in 40 countries were targeted, with total losses estimated to exceed €1 billion ($1.24 billion).

The mastermind behind the operation, a Ukrainian national referred to as “Denis K,” was arrested in Spain in 2018. Other members of the gang were reportedly Russian and Ukrainian nationals.

Related: Carbanak Source Code Discovered on VirusTotal

Related: “Cobalt” Hackers Use Google App Engine in Recent Attacks

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/KQQa1OxUnPI/two-carbanak-gang-members-sentenced-8-years-prison




Exabeam Lands $200M Investment, Replaces CEO

Exabeam, a late-stage startup in the data analytics and SIEM space, has landed a new $200 million funding round that values the company at $2.4 billion.

The announcement of Exabeam’s latest Series F funding, described as a “growth round,” coincides with news that co-founder and CEO Nir Polak will be replaced by former ForeScout chief executive Michael DeCesare.

Polak, who was Exabeam’s first CEO, will remain with the company and assume the role of board chairman.

DeCesare, a veteran cybersecurity executive who did leadership stints at McAfee and ForeScout Technologies, where he guided the company to a public markets exit in 2017.

Exabeam, founded in 2013 to jostle for market share in the SIEM (Security Information and Event Management) space, competes with the likes of Splunk, LogRhythm and IBM to help defenders store, log and parse corporate data at scale.

The company says it expects to use the new money to “fuel scale, product innovation and extend the company’s leadership” in what is described as a trusted cloud SecOps platform.

The latest investment was led by the Owl Rock division of Blue Owl Capital and supported by existing investors Acrew Capital, Lightspeed Venture Partners and Norwest Venture Partners. 

[ ANALYSIS: Inside the Battle to Control Enterprise Security Data Lakes ]

Entrepreneurs and investors are competing aggressively for ownership and control of the massive data lakes powering enterprise security programs and Exabeam is among a wave of entrenched companies providing realtime data monitoring and visibility to defenders.

“[This investment gives us the opportunity to triple down on our R&D efforts and continue engineering the most advanced UEBA, XDR and SIEM cloud security products,” the company said in a statement.

Exabeam says it has more than 400 resellers and about 500 technology integrations with leading IT and security companies including cloud network, data lake and endpoint vendors such as CrowdStrike, Okta and Snowflake.

RELATED: Microsoft’s 10 Billion Cybersecurity Business

RELATED: SIEM Platform Provider Raises $50 Million 

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/S-V2L7s7PIQ/exabeam-lands-200m-investment-replaces-ceo




Microsoft Creates Cybersecurity Council for the Public Sector in APAC

Looking to build stronger responses against cyberattacks in the Asia Pacific (APAC) region, Microsoft on Monday announced the creation of a cybersecurity council for the public sector in the region.

The Asia Pacific Public Sector Cybersecurity Executive Council consists of policy makers and influencers from Brunei, Indonesia, Korea, Malaysia, Philippines, Singapore, and Thailand.  It seeks seeks to accelerate collaboration between public and private cybersecurity organizations.

Policy makers from government and state agencies and cybersecurity experts from the public sector that form the council will work together to ensure improved communication and to promote the sharing of threat intelligence and technology, in an effort to battle evolving cyber threats in the region.

[ MORE AT: SecurityWeek’s 2021 Singapore ICS Cyber Security Virtual Conference ]

According to Microsoft, the initiative builds on the need for governments to build cyber-defense strategies and keep the region protected from attacks through strong collaboration with tech companies, given that private organizations own most of the necessary technology infrastructure.

“Cyberthreats and attacks are inevitable in this interconnected world, which is why our collective strength and collaboration as a community is imperative. [This is] the first step towards defending our communities in cyberspace with the founding members that include government leaders, policymakers, regulators, industry stakeholders across the region,” said Sherie Ng, General Manager, Public Sector, Microsoft Asia Pacific.

Related: Ransomware Takedowns Underscore Need for Private-Public Cybersecurity Collaboration

Related: Securing Today’s Networks Requires Consolidation and Collaboration

Related: The Positive Impact of the Pandemic on SecOps Collaboration

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/Qyw6ZrNda8c/microsoft-creates-cybersecurity-council-public-sector-apac




SonicWall Patches Command Injection Flaw in Firewall Management Application

SonicWall last week announced the availability of patches for a severe vulnerability in its Network Security Manager (NSM) product.

NSM is a firewall management application that provides the ability to monitor and manage all network security services from a single interface, as well as to automate tasks to improve security operations. SonicWall’s platform is available both for on-premises deployments and as SaaS (Software-as-a-Service).

Tracked as CVE-2021-20026 and featuring a CVSS score of 8.8, the recently patched vulnerability impacts on-premises versions of SonicWall NSM, but does not affect NSM SaaS versions.

The issue, SonicWall reveals in a security advisory, is an OS command injection flaw that could be exploited by an attacker who has already been able to authenticate to a vulnerable system. The fact that authentication is required for exploitation lowers the severity of the flaw.

An authenticated attacker can send specially crafted HTTP requests to the vulnerable application to exploit the vulnerability.

“This critical vulnerability potentially allows a user to execute commands on a device’s operating system with the highest system privileges (root),” SonicWall explains.

The vulnerability impacts SonicWall NSM On-Prem 2.2.0-R10 and earlier releases, and was addressed with the release of NSM versions 2.2.1-R6 and 2.2.1-R6 (Enhanced).

In its advisory, SonicWall is urging all customers to apply the available patches as soon as possible, to ensure they remain protected.

“SonicWall customers using the on-premises NSM versions outlined […] should upgrade to the respective patched version immediately,” the company says.

Related: SonicWall Zero-Day Exploited by Ransomware Group Before It Was Patched

Related: Three Zero-Day Flaws in SonicWall Email Security Product Exploited in Attacks

Related: SonicWall Patches SMA Zero-Day Vulnerability Exploited in Attacks

Related: SonicWall Says Internal Systems Targeted by Hackers Exploiting Zero-Day Flaws

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/dJ3zZ7jj7HU/sonicwall-patches-command-injection-flaw-firewall-management-application




Newly Disclosed Vulnerability Allows Remote Hacking of Siemens PLCs

Researchers at industrial cybersecurity firm Claroty have identified a serious vulnerability that can be exploited by a remote and unauthenticated attacker to hack some of the programmable logic controllers (PLCs) made by Siemens.

The vulnerability is tracked as CVE-2020-15782 and it has been described as a high-severity memory protection bypass issue that allows an attacker with network access to TCP port 102 to write or read data in protected memory areas.

Siemens PLCs can be hacked remotely via new vulnerabilitySiemens says the security hole impacts its SIMATIC S7-1200 and S7-1500 CPUs. The German industrial giant has released firmware updates for some of the impacted devices and it has provided workarounds for products for which patches have yet to be released.

According to Claroty, the vulnerability can be exploited to gain native code execution on Siemens S7 PLCs by bypassing the sandbox where engineering code normally runs and gaining direct access to the device’s memory.

The company’s researchers showed how an attacker could bypass protections and write shellcode directly into protected memory. An attack exploiting this vulnerability would be difficult to detect, the researchers claim.

“Escaping the sandbox means an attacker would be able to read and write from anywhere on the PLC, and could patch an existing VM opcode in memory with malicious code to root the device,” Claroty researchers explained in a blog post published on Friday.

“Claroty, for example, was able to inject ARM/MIPS shellcode directly to an internal operating system structure in such a way that when the operating system uses a specific opcode that we chose, our malicious shellcode would execute, giving us remote code execution. We used this technique to install a kernel-level program with some functionality that is completely hidden to the operating system,” they added.

Claroty’s blog post describes the PLC sandbox and the role CVE-2020-15782 could play in an attack.

Related: Serious Vulnerabilities Found in Schneider Electric Power Meters

Related: Unprotected Private Key Allows Remote Hacking of Rockwell Controllers

Related: Vulnerabilities in CodeMeter Licensing Product Expose ICS to Remote Attacks

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/hSgTTqLiIR0/newly-disclosed-vulnerability-allows-remote-hacking-siemens-plcs




FBI Shares IOCs for APT Attacks Exploiting Fortinet Vulnerabilities

The FBI on Thursday published indicators of compromise (IOCs) associated with the continuous exploitation of Fortinet FortiOS vulnerabilities in attacks targeting commercial, government, and technology services networks.

In early April, the FBI along with the Cybersecurity and Infrastructure Security Agency (CISA) warned that threat actors had been targeting serious security holes in Fortinet’s flagship operating system FortiOS for initial access into victims’ networks.

The targeted bugs include CVE-2018-13379 (a path traversal in the FortiOS SSL VPN web portal), CVE-2020-12812 (a bypass of FortiOS SSL VPN two-factor authentication), and CVE-2019-5591 (default configurations ship without LDAP server identity verification).

While initial activity only involved scanning for devices vulnerable to the FortiOS SSL VPN web portal flaw (on ports 4443, 8443, and 10443), as well as enumeration of devices potentially impacted by the other two bugs, the attackers have since moved to network compromise and additional malicious activity.

“As of at least May 2021, an APT actor group almost certainly exploited a Fortigate appliance to access a webserver hosting the domain for a U.S. municipal government. The APT actors likely created an account with the username ‘elie’ to further enable malicious activity on the network,” the FBI now says.

The agency says that another account likely associated with this activity is “WADGUtilityAccount,” which, similar to “elie,” threat actors might have established on active directories, domain controllers, servers, and workstations. Network administrators should also look for other unrecognized accounts.

Additionally, admins should be wary of executable files such as Audio.exe (or frpc.exe) and Frps.exe, of outbound FTP traffic on port 443, a scheduled task named “SynchronizeTimeZone,” and the use of tools such as Mimikatz, MinerGate, WinPEAS, SharpWMI, BitLocker, WinRARwhere, and FileZilla. Some of these might be benign, unless used when unexpected, the FBI notes.

Administrators are also advised to take all the necessary measures to ensure the security of networks, including keeping systems patched and continuously updated, implementing network segmentation and multi-factor authentication, applying the principle of least privilege, keeping data backed up, employing malware detection tools, and periodically checking the environment for suspicious activity.

Related: Cring Ransomware Targets Industrial Organizations

Related: Industry Reactions to FBI Cleaning Up Hacked Exchange Servers: Feedback Friday

Related: FBI: 16 Conti Ransomware Attacks Targeted Healthcare, First Responders in U.S.

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/rrxefi0cSyQ/fbi-shares-iocs-apt-attacks-exploiting-fortinet-vulnerabilities




U.S. Charges 22 in Stolen Payment Cards Crackdown

The U.S. Justice Department this week announced indictments against 22 individuals who allegedly purchased and used payment cards stolen from a national retail chain.

Using point-of-sale malware installed at multiple retail locations of the target company, threat actors stole information of over three million payment cards, including credit, debit, and gift cards used at over 400 of the company’s retail stores.

According to the indictment, the co-conspirators then sold the hijacked data for $4 million in Bitcoin to an individual who sold it to thousands of other people, including the 22 now facing charges by the U.S. Department of Justice.

Twenty of the defendants have been arrested while the other two remain are large, likely abroad, the authorities said.

The 22 individuals are charged with using the payment card information to make various purchases, including at gas stations, hotels, and restaurants.

The indictment alleges that one of the defendants purchased more than 13,000 payment cards stolen from the retail chain, while another purchased more than 6,000 such cards. Others purchased between 2,000 and 4,000 payment cards. 

According to the Justice Department, each defendant faces up to 20 years in federal prison for charges of wire fraud and a two-year mandatory, consecutive prison sentence for aggravated identity theft.

Related: US Charges Swiss ‘Hacktivist’ for Data Theft and Leaks

Related: U.S. Charges North Korean Hackers Over $1.3B Bank Heists

Related: US Indicts Head of Alleged Crime Chat Comms Service

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/bwDeoUDUfuY/us-charges-22-stolen-payment-cards-crackdown




Japanese Ministries Confirm Impact from Fujitsu Data Breach

Japan’s Ministry of Foreign Affairs and Ministry of Land, Infrastructure, Transport and Tourism this week confirmed impact from a data breach at service provider Fujitsu Limited.

Earlier this week, the Japanese multinational provider of IT services and products confirmed it suffered a cyberattack resulting in unauthorized access to ProjectWEB, a tool that allows organizations to share data within and outside their environments.

The company said that it stopped the service, to prevent further unauthorized access, but confirmed that “some of the information entrusted to us by our customers was stolen,” without providing further information on the matter.

“The scope and cause of this incident are currently under investigation, and the operation of ProjectWEB has been suspended to prevent further unauthorized access,” Fujitsu said.

On Wednesday, Japan’s Ministry of Foreign Affairs announced that it was impacted by the incident, saying that study material was stolen, and that some personally identifiable information might have been affected as well.

The ministry notes that the affected individuals were informed of the data leak and that the study information doesn’t impact its systems or operations.

Also on Wednesday, the Ministry of Land, Infrastructure, Transport and Tourism said that approximately 76,000 email addresses of individuals both within and outside the ministry were likely compromised in the incident.

“No unauthorized access has been confirmed to the ministry’s system,” the ministry said, adding that it experienced no interruptions as result of the data leak. The ministry also revealed plans to contact the individuals whose email addresses were compromised.

Related: City of Chicago Hit by Data Breach at Law Firm Jones Day

Related: Cybercriminals Publish Data Stolen From Shell, Universities

Related: Belden Says Health-Related Information Exposed in Data Breach

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/0rviAC4e-CU/japanese-ministries-confirm-impact-fujitsu-data-breach




Vulnerabilities in Visual Studio Code Extensions Expose Developers to Attacks

Vulnerabilities in Visual Studio Code extensions could be exploited by malicious attackers to steal valuable information from developers and even compromise organizations, researchers with open-source software security firm Snyk say.

Generally considered secure, VS Code extensions could expose millions of developers to malicious attacks, potentially leading to the compromise of information stored on developer machines, such as credentials, or even opening the route to further attacks.

Snyk’s security researchers analyzed popular VS Code extensions that start web servers, which are typically accessible locally via a browser, and discovered that malicious actors could exploit vulnerabilities in the web server to target the developers using these extensions. The attacks demonstrated by Snyk only require the victim to click on a link.

“By leveraging this attack scenario a malicious actor can steal important pieces of information, like RSA keys, and eventually access version control systems (VCS) or even connect to production servers and compromise the security of an entire organization,” Snyk notes.

One of the vulnerable extensions, LaTeX Workshop, which has approximately 1.2 million installs, starts an HTTP server and a WebSocket server (on a random port) when the developer opens a .tex file in the editor, to allow them to preview a PDF file in the browser.

Because the input from the WebSocket client to the openExternal VS Code API method was not sanitized, however, the extension was vulnerable to command injection exploitable by a malicious web page able to connect to the extension’s local WebSocket server (by checking all possible ports).

The Open In Default Browser extension, which starts an HTTP server to preview pages in the browser, was found to contain a path traversal bug that a malicious actor could exploit to steal files from the machine. While same-origin policy (SOP) protections would prevent exploitation, a cross-site scripting (XSS) payload could be crafted to help with the process.

Snyk also discovered that the Rainbow Fart extension (60,000 installs), which plays a sound when the user types specific keywords, contained a Zip Slip vulnerability that could be abused to overwrite arbitrary files on the target computer, and possibly achieve arbitrary code execution.

In some cases, the vulnerable VS Code extensions could have leveraged existing NPM packages to implement the desired functionality instead of using custom code — this can help avoid introducing vulnerabilities.

“What has been clear for third-party dependencies is also now clear for IDE plugins — they introduce an inherent risk to an application. They’re potentially dangerous both because of their custom written code pieces and the dependencies they are built upon. What has been shown here for VS Code might be applicable to other IDEs as well,” Snyk concludes.

Related: Vulnerability in CocoaPods Dependency Manager Exposed Millions of Apps

Related: Library Dependencies and the Open Source Supply Chain Nightmare

Related: Software Dependencies Exposed Microsoft, Apple to High-Impact Attacks

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/qXeUDOFklUs/vulnerabilities-visual-studio-code-extensions-expose-developers-attacks