#cve2023 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve2023, aggregated by home.social.
-
A privilege escalation from Chrome extensions (2023)
https://0x44.xyz/blog/cve-2023-4369/
#HackerNews #privilegeEscalation #ChromeExtensions #CVE2023 #cybersecurity #hackernews
-
A privilege escalation from Chrome extensions (2023)
https://0x44.xyz/blog/cve-2023-4369/
#HackerNews #privilegeEscalation #ChromeExtensions #CVE2023 #cybersecurity #hackernews
-
🚨 Cybersecurity alert! Protect your system from the Black Lotus vulnerability (CVE-2023-24932) targeting Secure Boot. Here's what admins need to know to safeguard their devices. 🛡️ Don’t wait until it’s too late. Learn how to act now #CyberSecurity #InfoSec #CVE2023
https://pupuweb.com/how-to-protect-your-system-from-black-lotus-vulnerability-cve-2023-24932/
-
Foxit PDF Reader Users Targeted by Malicious PDF Exploit
Date: May 15, 2024
CVE: CVE-2023-36033
Vulnerability Type: Remote Code Execution (RCE)
CWE: [[CWE-20]], [[CWE-78]], [[CWE-94]]
Sources: GBHackers, Checkpoint ResearchIssue Summary
Researchers have identified a critical vulnerability in Foxit PDF Reader that allows attackers to execute malicious code on users' systems by exploiting a design flaw in the application's security warnings. The flaw makes it easy for attackers to trick users into approving malicious actions, leading to unauthorized access and data theft.
Technical Key Findings
The vulnerability stems from Foxit Reader's handling of security warnings, which default to an "OK" option. This flaw enables attackers to craft malicious PDFs that, when opened, prompt the user to approve actions unknowingly. Once approved, these actions can download and execute malicious code from a remote server, bypassing standard security detections.
Vulnerable Products
- Foxit Reader
Impact Assessment
Exploitation of this vulnerability can lead to severe consequences, including unauthorized access to sensitive data, remote control of the affected device, and the ability to deploy various malware such as VenomRAT, Agent-Tesla, and others. This can result in data breaches, espionage, and further propagation of malware.
Patches or Workarounds
Foxit has acknowledged the issue and that it would be resolved in version 2024 3.
Tags
#FoxitPDF #CVE2023-36033 #RemoteCodeExecution #Malware #CyberSecurity #APT #VulnerabilityPatch #DataBreach
-
Foxit PDF Reader Users Targeted by Malicious PDF Exploit
Date: May 15, 2024
CVE: CVE-2023-36033
Vulnerability Type: Remote Code Execution (RCE)
CWE: [[CWE-20]], [[CWE-78]], [[CWE-94]]
Sources: GBHackers, Checkpoint ResearchIssue Summary
Researchers have identified a critical vulnerability in Foxit PDF Reader that allows attackers to execute malicious code on users' systems by exploiting a design flaw in the application's security warnings. The flaw makes it easy for attackers to trick users into approving malicious actions, leading to unauthorized access and data theft.
Technical Key Findings
The vulnerability stems from Foxit Reader's handling of security warnings, which default to an "OK" option. This flaw enables attackers to craft malicious PDFs that, when opened, prompt the user to approve actions unknowingly. Once approved, these actions can download and execute malicious code from a remote server, bypassing standard security detections.
Vulnerable Products
- Foxit Reader
Impact Assessment
Exploitation of this vulnerability can lead to severe consequences, including unauthorized access to sensitive data, remote control of the affected device, and the ability to deploy various malware such as VenomRAT, Agent-Tesla, and others. This can result in data breaches, espionage, and further propagation of malware.
Patches or Workarounds
Foxit has acknowledged the issue and that it would be resolved in version 2024 3.
Tags
#FoxitPDF #CVE2023-36033 #RemoteCodeExecution #Malware #CyberSecurity #APT #VulnerabilityPatch #DataBreach
-
"🚨 Critical OpenShift Update 🚨 - Securing Kubernetes Deployments"
Red Hat has released a critical update for OpenShift Container Platform 4.12.51, addressing multiple security vulnerabilities and enhancing stability. This update patches several security issues, including a notable path traversal and RCE vulnerability in go-git (CVE-2023-49569) and a DoS risk in go-git clients (CVE-2023-49568). Users are urged to apply this critical update to maintain system security and integrity.
Tags: #OpenShift #RedHat #CyberSecurity #Kubernetes #PatchTuesday #CVE2023
Read more about the update: RHSA-2024:1052
-
"🚨 Critical OpenShift Update 🚨 - Securing Kubernetes Deployments"
Red Hat has released a critical update for OpenShift Container Platform 4.12.51, addressing multiple security vulnerabilities and enhancing stability. This update patches several security issues, including a notable path traversal and RCE vulnerability in go-git (CVE-2023-49569) and a DoS risk in go-git clients (CVE-2023-49568). Users are urged to apply this critical update to maintain system security and integrity.
Tags: #OpenShift #RedHat #CyberSecurity #Kubernetes #PatchTuesday #CVE2023
Read more about the update: RHSA-2024:1052
-
"🚨 Juniper Secure Analytics Patch Alert 🚨 - CVE-2023-37920 Leads the Charge with a CVSS 9.8 Rating!"
Juniper Networks has issued a critical update for Juniper Secure Analytics (JSA), patching multiple vulnerabilities, with CVE-2023-37920 standing out with a CVSS score of 9.8. These flaws span various components and could lead to severe consequences including unauthorized access and denial of service. Users are urged to update to 7.5.0 UP7 IF05 to mitigate these risks. 🛡️💻🔐
Tags: #CyberSecurity #JuniperNetworks #VulnerabilityManagement #PatchTuesday #InfoSec #NetworkSecurity #CVE2023
For more details, visit the Juniper Support Portal.
-
"🚨 Juniper Secure Analytics Patch Alert 🚨 - CVE-2023-37920 Leads the Charge with a CVSS 9.8 Rating!"
Juniper Networks has issued a critical update for Juniper Secure Analytics (JSA), patching multiple vulnerabilities, with CVE-2023-37920 standing out with a CVSS score of 9.8. These flaws span various components and could lead to severe consequences including unauthorized access and denial of service. Users are urged to update to 7.5.0 UP7 IF05 to mitigate these risks. 🛡️💻🔐
Tags: #CyberSecurity #JuniperNetworks #VulnerabilityManagement #PatchTuesday #InfoSec #NetworkSecurity #CVE2023
For more details, visit the Juniper Support Portal.
-
"Critical RCE Flaw Uncovered in SolarWinds Access Rights Manager 🚨 #CVE2023-40057"
A newly discovered deserialization vulnerability in SolarWinds Access Rights Manager (versions up to 2023.2.2) poses a severe risk, enabling remote code execution. Classified as very critical with a CVSS score of 8.9, this flaw (CVE-2023-40057) could allow authenticated users to execute arbitrary code remotely. Despite its high impact on confidentiality, integrity, and availability, no exploit is currently available. The vulnerability underscores the importance of validating deserialized data to prevent unauthorized access. No mitigation measures have been identified yet, emphasizing the need for heightened vigilance and potential product alternatives.
Stay informed: CVE-2023-40057 Details
Tags: #CyberSecurity #Vulnerability #SolarWinds #RemoteCodeExecution #RCE #Deserialization #CVE2023-40057 #InfoSec 🛡️💡🔒
-
"Critical RCE Flaw Uncovered in SolarWinds Access Rights Manager 🚨 #CVE2023-40057"
A newly discovered deserialization vulnerability in SolarWinds Access Rights Manager (versions up to 2023.2.2) poses a severe risk, enabling remote code execution. Classified as very critical with a CVSS score of 8.9, this flaw (CVE-2023-40057) could allow authenticated users to execute arbitrary code remotely. Despite its high impact on confidentiality, integrity, and availability, no exploit is currently available. The vulnerability underscores the importance of validating deserialized data to prevent unauthorized access. No mitigation measures have been identified yet, emphasizing the need for heightened vigilance and potential product alternatives.
Stay informed: CVE-2023-40057 Details
Tags: #CyberSecurity #Vulnerability #SolarWinds #RemoteCodeExecution #RCE #Deserialization #CVE2023-40057 #InfoSec 🛡️💡🔒
-
"🚨 CVE-2023-28807 - Domain Fronting Evasion in ZIA 🚨"
An evasion technique identified as CVE-2023-28807, allows attackers to bypass Zscaler Internet Access (ZIA)'s domain fronting detection by exploiting a mismatch between Connect Host and Server Name Indication (SNI) in Client Hello messages. The vulnerability exploits how ZIA handles the SNI field during the TLS handshake process. The SNI is intended to indicate which host the client wants to connect to within a shared hosting environment, allowing the server to present the correct certificate for that host. However, due to this vulnerability, an attacker can manipulate the SNI in such a way that the security mechanisms fail to correctly identify and filter malicious traffic, enabling the attacker to hide malicious activities within what appears to be legitimate traffic.
This vulnerability, discovered and addressed by Zscaler. Users are urged to upgrade to version 6.2r.290 to mitigate this risk. 🛡️💻🔐Tags: #Cybersecurity #CVE2023 #DomainFronting #Zscaler #NetworkSecurity #EvasionTechniques #MITREATTACK MITRE - T1587.003 🌍🔒🔍
-
"🚨 CVE-2023-28807 - Domain Fronting Evasion in ZIA 🚨"
An evasion technique identified as CVE-2023-28807, allows attackers to bypass Zscaler Internet Access (ZIA)'s domain fronting detection by exploiting a mismatch between Connect Host and Server Name Indication (SNI) in Client Hello messages. The vulnerability exploits how ZIA handles the SNI field during the TLS handshake process. The SNI is intended to indicate which host the client wants to connect to within a shared hosting environment, allowing the server to present the correct certificate for that host. However, due to this vulnerability, an attacker can manipulate the SNI in such a way that the security mechanisms fail to correctly identify and filter malicious traffic, enabling the attacker to hide malicious activities within what appears to be legitimate traffic.
This vulnerability, discovered and addressed by Zscaler. Users are urged to upgrade to version 6.2r.290 to mitigate this risk. 🛡️💻🔐Tags: #Cybersecurity #CVE2023 #DomainFronting #Zscaler #NetworkSecurity #EvasionTechniques #MITREATTACK MITRE - T1587.003 🌍🔒🔍
-
"🔐 #GitLabSecurityAlert - Multiple Critical Vulnerabilities Patched in GitLab 🚨"
📰 GitLab has released critical updates (16.7.2, 16.6.4, 16.5.6) addressing several security vulnerabilities, including a critical account takeover flaw and a Slack/Mattermost integration exploit. Users are urged to update immediately.
1️⃣ The most severe, CVE-2023-7028, allowed password reset emails to be sent to unverified addresses (CVSS 10.0).
2️⃣ CVE-2023-5356 permitted unauthorized execution of slash commands in Slack/Mattermost integrations (CVSS 9.6).
3️⃣ CVE-2023-4812 involved bypassing CODEOWNERS approval in merge requests (CVSS 7.6).
4️⃣ CVE-2023-6955, a medium severity issue, related to improper access control in GitLab Remote Development (CVSS 6.6).
5️⃣ The least critical, CVE-2023-2030, allowed alteration of metadata in signed commits (CVSS 3.5).Kudos to the security researchers (@asterion04, @yvvdwf, @ali_shehab, @lotsofloops on HackerOne) and GitLab's @j.seto for identifying these issues. Stay secure, folks!
Source: GitLab Release Notes
Author: Greg MyersTags: #Cybersecurity #Vulnerability #GitLab #CVE2023 #PatchUpdate #InfoSec #HackerOne #DevSecOps 🛡️💻🔧
-
"🔐 #GitLabSecurityAlert - Multiple Critical Vulnerabilities Patched in GitLab 🚨"
📰 GitLab has released critical updates (16.7.2, 16.6.4, 16.5.6) addressing several security vulnerabilities, including a critical account takeover flaw and a Slack/Mattermost integration exploit. Users are urged to update immediately.
1️⃣ The most severe, CVE-2023-7028, allowed password reset emails to be sent to unverified addresses (CVSS 10.0).
2️⃣ CVE-2023-5356 permitted unauthorized execution of slash commands in Slack/Mattermost integrations (CVSS 9.6).
3️⃣ CVE-2023-4812 involved bypassing CODEOWNERS approval in merge requests (CVSS 7.6).
4️⃣ CVE-2023-6955, a medium severity issue, related to improper access control in GitLab Remote Development (CVSS 6.6).
5️⃣ The least critical, CVE-2023-2030, allowed alteration of metadata in signed commits (CVSS 3.5).Kudos to the security researchers (@asterion04, @yvvdwf, @ali_shehab, @lotsofloops on HackerOne) and GitLab's @j.seto for identifying these issues. Stay secure, folks!
Source: GitLab Release Notes
Author: Greg MyersTags: #Cybersecurity #Vulnerability #GitLab #CVE2023 #PatchUpdate #InfoSec #HackerOne #DevSecOps 🛡️💻🔧
-
"🚨 iPhone Triangulation: A New Era in Hardware-Level Cyber Espionage 🚨"
Kaspersky's recent findings reveal a concerning truth in the world of cyber warfare. They've named it "Operation Triangulation.". This spyware campaign, active since 2019, hijacks iPhones using four zero-day vulnerabilities, including CVE-2023-41990, CVE-2023-32434, CVE-2023-32435, and CVE-2023-38606. The technical report on "Operation Triangulation: The Last Hardware Mystery" reveals a sophisticated cyberattack targeting iPhones. This attack utilized a zero-click iMessage exploit involving four zero-days, capable of affecting iOS versions up to 16.2.
The exploit chain began with a malicious iMessage attachment exploiting the CVE-2023-41990 vulnerability in an undocumented TrueType font instruction. This led to privilege escalation through a complex JavaScript exploit, leveraging the JavaScriptCore debugging feature and an integer overflow vulnerability (CVE-2023-32434) for broader access.
A key aspect of this attack was bypassing hardware-based security in recent iPhone models using a hardware feature of Apple-designed SoCs, mitigated as CVE-2023-38606. The exploit's sophistication and ability to circumvent advanced hardware-based protections leave us with the big question; Since this feature is not used by the firmware, how did the attackers know how to take advantage of it?
#CyberSecurity #InfoSec #iPhoneTriangulation #ZeroDay #CVE2023 #AppleSecurity #HardwareExploits #Kaspersky #BleepingComputer 📱🔒💻
Sources:
- BleepingComputer: Article by Bill Toulas
- Securelist: Analysis by Boris Larin & Team
-
"🚨 iPhone Triangulation: A New Era in Hardware-Level Cyber Espionage 🚨"
Kaspersky's recent findings reveal a concerning truth in the world of cyber warfare. They've named it "Operation Triangulation.". This spyware campaign, active since 2019, hijacks iPhones using four zero-day vulnerabilities, including CVE-2023-41990, CVE-2023-32434, CVE-2023-32435, and CVE-2023-38606. The technical report on "Operation Triangulation: The Last Hardware Mystery" reveals a sophisticated cyberattack targeting iPhones. This attack utilized a zero-click iMessage exploit involving four zero-days, capable of affecting iOS versions up to 16.2.
The exploit chain began with a malicious iMessage attachment exploiting the CVE-2023-41990 vulnerability in an undocumented TrueType font instruction. This led to privilege escalation through a complex JavaScript exploit, leveraging the JavaScriptCore debugging feature and an integer overflow vulnerability (CVE-2023-32434) for broader access.
A key aspect of this attack was bypassing hardware-based security in recent iPhone models using a hardware feature of Apple-designed SoCs, mitigated as CVE-2023-38606. The exploit's sophistication and ability to circumvent advanced hardware-based protections leave us with the big question; Since this feature is not used by the firmware, how did the attackers know how to take advantage of it?
#CyberSecurity #InfoSec #iPhoneTriangulation #ZeroDay #CVE2023 #AppleSecurity #HardwareExploits #Kaspersky #BleepingComputer 📱🔒💻
Sources:
- BleepingComputer: Article by Bill Toulas
- Securelist: Analysis by Boris Larin & Team
-
"⚠️ Alert: Google Chrome Zero-Day CVE-2023-7024 Exploited in the Wild! 🌐💥"
Google's latest patch addresses a critical zero-day vulnerability in Chrome, CVE-2023-7024. Identified as a heap-based buffer overflow in WebRTC, it's exploited in the wild. Chrome versions before 120.0.6099.129 are vulnerable. 🚨
Details: CVE-2023-7024, discovered by Google TAG, affects several browsers using WebRTC. It's the eighth zero-day patched by Google this year, underscoring the evolving cybersecurity landscape.
Mitigation: Users should urgently update to Chrome 120.0.6099.129/130 (for Windows) or 120.0.6099.129 (for Mac/Linux) to protect against this and other security fixes included in recent Chrome updates. 🛡️
Source: Qualys ThreatPROTECT by Diksha Ojha; Chrome Releases Blog
Tags: #Cybersecurity #GoogleChrome #ZeroDay #CVE2023 #WebRTC #UpdateNow #CyberAttack #InfoSecExchange
-
"⚠️ Alert: Google Chrome Zero-Day CVE-2023-7024 Exploited in the Wild! 🌐💥"
Google's latest patch addresses a critical zero-day vulnerability in Chrome, CVE-2023-7024. Identified as a heap-based buffer overflow in WebRTC, it's exploited in the wild. Chrome versions before 120.0.6099.129 are vulnerable. 🚨
Details: CVE-2023-7024, discovered by Google TAG, affects several browsers using WebRTC. It's the eighth zero-day patched by Google this year, underscoring the evolving cybersecurity landscape.
Mitigation: Users should urgently update to Chrome 120.0.6099.129/130 (for Windows) or 120.0.6099.129 (for Mac/Linux) to protect against this and other security fixes included in recent Chrome updates. 🛡️
Source: Qualys ThreatPROTECT by Diksha Ojha; Chrome Releases Blog
Tags: #Cybersecurity #GoogleChrome #ZeroDay #CVE2023 #WebRTC #UpdateNow #CyberAttack #InfoSecExchange
-
"⚠️ Critical Apache Struts Vulnerability Alert! CVE-2023-50164 🚨"
Hackers are exploiting a critical vulnerability in Apache Struts (CVE-2023-50164), a popular Java EE web app framework used widely in various industries. This flaw allows unauthorized remote code execution, posing a severe threat to organizations using Struts versions 2.0.0 through 2.5.32 and 6.0.0 through 6.3.0.1. Attackers can manipulate file upload parameters for path traversal, leading to malicious file uploads and potentially gaining control over the server. An immediate upgrade to Struts 2.5.33 or 6.3.0.2 is vital to mitigate this risk.
Source: BleepingComputer, [trganda.github.io](https://trganda.github.io/notes/security/vulnerabilities/apache-struts/Apache-Struts-Remote-Code-Execution-Vulnerability-(-S2-066-CVE-2023-50164), Qualys ThreatPROTECT
Author Credits: Bill Toulas (BleepingComputer), Diksha Ojha (Qualys ThreatPROTECT)
Tags: #CyberSecurity #ApacheStruts #Vulnerability #CVE2023-50164 #RemoteCodeExecution #InfoSec
-
"⚠️ Critical Apache Struts Vulnerability Alert! CVE-2023-50164 🚨"
Hackers are exploiting a critical vulnerability in Apache Struts (CVE-2023-50164), a popular Java EE web app framework used widely in various industries. This flaw allows unauthorized remote code execution, posing a severe threat to organizations using Struts versions 2.0.0 through 2.5.32 and 6.0.0 through 6.3.0.1. Attackers can manipulate file upload parameters for path traversal, leading to malicious file uploads and potentially gaining control over the server. An immediate upgrade to Struts 2.5.33 or 6.3.0.2 is vital to mitigate this risk.
Source: BleepingComputer, [trganda.github.io](https://trganda.github.io/notes/security/vulnerabilities/apache-struts/Apache-Struts-Remote-Code-Execution-Vulnerability-(-S2-066-CVE-2023-50164), Qualys ThreatPROTECT
Author Credits: Bill Toulas (BleepingComputer), Diksha Ojha (Qualys ThreatPROTECT)
Tags: #CyberSecurity #ApacheStruts #Vulnerability #CVE2023-50164 #RemoteCodeExecution #InfoSec
-
🚨 Une faille critique nommée Citrix Bleed (CVE-2023-4966) affecte les systèmes Citrix NetScaler, permettant le détournement de sessions authentifiées et la contournement de l'authentification à facteurs multiples. Plusieurs grandes entreprises, dont Boeing et Allen & Overy, ont été ciblées par des cyberattaques exploitant cette vulnérabilité, avec des suspicions de cyberespionnage et des actions criminelles par des groupes comme LockBit 3.0. 🛡️ Il est urgent de vérifier et sécuriser les systèmes Citrix pour se prémunir contre ces menaces qui restent actives. #CyberSécurité #CitrixBleed #CVE2023-4966
https://www.lemagit.fr/actualites/366559556/Citrix-Bleed-la-liste-des-victimes-de-lexploitation-de-la-vulnerabilite-sallonge -
🚨 Une faille critique nommée Citrix Bleed (CVE-2023-4966) affecte les systèmes Citrix NetScaler, permettant le détournement de sessions authentifiées et la contournement de l'authentification à facteurs multiples. Plusieurs grandes entreprises, dont Boeing et Allen & Overy, ont été ciblées par des cyberattaques exploitant cette vulnérabilité, avec des suspicions de cyberespionnage et des actions criminelles par des groupes comme LockBit 3.0. 🛡️ Il est urgent de vérifier et sécuriser les systèmes Citrix pour se prémunir contre ces menaces qui restent actives. #CyberSécurité #CitrixBleed #CVE2023-4966
https://www.lemagit.fr/actualites/366559556/Citrix-Bleed-la-liste-des-victimes-de-lexploitation-de-la-vulnerabilite-sallonge -
"🚨 NGINX Ingress Vulnerabilities Exposed! 🚨"
Three new vulnerabilities have been identified in the NGINX ingress controller for Kubernetes. These vulnerabilities, tagged as CVE-2023-5043, CVE-2023-5044, and CVE-2022-4886, could potentially allow attackers to steal secret credentials from the cluster. 🕵️♂️🔓
CVE-2023-5043 & CVE-2023-5044: These vulnerabilities can be exploited by attackers who can control the Ingress object's configuration. By using the annotation fields “configuration-snippet” or “permanent-redirect”, attackers can inject arbitrary code into the ingress controller process, gaining access to the service account token of the ingress controller. This token has a ClusterRole, enabling reading of all Kubernetes secrets in the cluster. 😱
CVE-2022-4886: This vulnerability lies in the way the “path” field is used in the Ingress routing definitions. A flaw in the validation of the inner path can lead to exposure of the service account token, which is used for authentication against the API server. 🚫
Mitigation steps include updating NGINX to version 1.19 and enabling the “--enable-annotation-validation” command line configuration. 🛡️
These vulnerabilities underscore the importance of securing ingress controllers, given their high privilege scope and potential exposure to external traffic.
Source: ARMO Blog by Ben Hirschberg, CTO & Co-founder.
Tags: #NGINX #Kubernetes #Vulnerability #CyberSecurity #IngressController #CVE2023 #CVE2022 🌐🔐🔍
-
"🚨 NGINX Ingress Vulnerabilities Exposed! 🚨"
Three new vulnerabilities have been identified in the NGINX ingress controller for Kubernetes. These vulnerabilities, tagged as CVE-2023-5043, CVE-2023-5044, and CVE-2022-4886, could potentially allow attackers to steal secret credentials from the cluster. 🕵️♂️🔓
CVE-2023-5043 & CVE-2023-5044: These vulnerabilities can be exploited by attackers who can control the Ingress object's configuration. By using the annotation fields “configuration-snippet” or “permanent-redirect”, attackers can inject arbitrary code into the ingress controller process, gaining access to the service account token of the ingress controller. This token has a ClusterRole, enabling reading of all Kubernetes secrets in the cluster. 😱
CVE-2022-4886: This vulnerability lies in the way the “path” field is used in the Ingress routing definitions. A flaw in the validation of the inner path can lead to exposure of the service account token, which is used for authentication against the API server. 🚫
Mitigation steps include updating NGINX to version 1.19 and enabling the “--enable-annotation-validation” command line configuration. 🛡️
These vulnerabilities underscore the importance of securing ingress controllers, given their high privilege scope and potential exposure to external traffic.
Source: ARMO Blog by Ben Hirschberg, CTO & Co-founder.
Tags: #NGINX #Kubernetes #Vulnerability #CyberSecurity #IngressController #CVE2023 #CVE2022 🌐🔐🔍
-
"🚨 #CitrixBleed Exploit Unleashed! Hackers Hijack NetScaler Accounts 🚨"
A new proof-of-concept (PoC) exploit for the 'Citrix Bleed' vulnerability (CVE-2023-4966) has emerged, enabling attackers to snatch authentication session cookies from susceptible Citrix NetScaler ADC and NetScaler Gateway appliances. This critical-severity flaw, which Citrix addressed on October 10, was exploited as a zero-day in limited attacks since late August 2023. Assetnote researchers have now shared an in-depth analysis of the exploitation method and even released a PoC exploit on GitHub. The vulnerability stems from an unauthenticated buffer-related issue, which, when exploited, can lead to buffer over-reads. By leveraging this flaw, attackers can retrieve session cookies, granting them unrestricted access to vulnerable devices. Given the public availability of this exploit, there's an anticipated surge in attacks targeting Citrix Netscaler devices. System admins are strongly urged to apply patches immediately.
Source: BleepingComputer
Tags: #Cybersecurity #Citrix #NetScaler #CVE2023 #Exploit #PoC #Assetnote #Vulnerability #InfoSec
Author: Bill Toulas
-
"🚨 #CitrixBleed Exploit Unleashed! Hackers Hijack NetScaler Accounts 🚨"
A new proof-of-concept (PoC) exploit for the 'Citrix Bleed' vulnerability (CVE-2023-4966) has emerged, enabling attackers to snatch authentication session cookies from susceptible Citrix NetScaler ADC and NetScaler Gateway appliances. This critical-severity flaw, which Citrix addressed on October 10, was exploited as a zero-day in limited attacks since late August 2023. Assetnote researchers have now shared an in-depth analysis of the exploitation method and even released a PoC exploit on GitHub. The vulnerability stems from an unauthenticated buffer-related issue, which, when exploited, can lead to buffer over-reads. By leveraging this flaw, attackers can retrieve session cookies, granting them unrestricted access to vulnerable devices. Given the public availability of this exploit, there's an anticipated surge in attacks targeting Citrix Netscaler devices. System admins are strongly urged to apply patches immediately.
Source: BleepingComputer
Tags: #Cybersecurity #Citrix #NetScaler #CVE2023 #Exploit #PoC #Assetnote #Vulnerability #InfoSec
Author: Bill Toulas
-
🛡️ Crucial Discovery in Cybersecurity: CVE-2023-4911
In the ever-evolving world of cybersecurity, we've uncovered a game-changing vulnerability in the GNU C Library's dynamic loader, ld.so. Let's dive into the details, explore the impact, and discuss how vigilance and collaboration remain our best defense. RELIANOID certainly is NOT affected 😎. Stay tuned for the latest insights!
https://www.relianoid.com/.../looney-tunables-a-deep.../
#Cybersecurity #Vulnerability #SecurityResearch #LinuxSecurity #GNUCLibrary #CVE2023 #InfoSec -
🚨 #Cybersecurity Alert: DreamBus Botnet is back and exploiting a new vulnerability in RocketMQ servers (CVE-2023-33246) for remote code execution. Juniper Threat Labs reports multiple attacks installing the DreamBus malware.
Key Points:
Vulnerability Disclosure:
- In May 2023, a vulnerability (CVE-2023-33246) was disclosed that affects RocketMQ servers and allows for remote code execution.
Exploitation by DreamBus Botnet:
- Juniper Threat Labs detected multiple attacks exploiting this vulnerability to install the DreamBus bot, a malware strain last seen in 2021.
Attack Timeline:
- Attacks began in early June and peaked in mid-June.
- Attackers targeted the default port for RocketMQ (10911) and at least seven other ports.
Reconnaissance and Malicious Activities:
- Initial attacks used an open-source tool called 'interactsh' for reconnaissance.
- From June 19th, attackers began using a malicious bash script named "reketed" to download and execute payloads.
- Two methods were used for payload retrieval: TOR proxy service and a specific IP address.
Technical Details:
- The 'reketed' bash script downloads the DreamBus main module from a TOR hidden service.
- Both 'reketed' and the DreamBus main module had zero detections on VirusTotal at the time of analysis.
- The DreamBus main module is an ELF Linux binary packed with UPX, making static detection challenging.
Malware Capabilities:
- The malware can perform various functions like downloading other modules and sending notifications to the server.
- It can send requests to different paths on the TOR onion service for various actions like pinging the server, downloading and executing the main module, installing a Monero miner, and executing bash scripts.
Implications:
- The attacks add complexity to potential forensic investigations and pose a significant threat to RocketMQ servers.
The article provides a comprehensive look into the DreamBus botnet's resurgence, its exploitation of the RocketMQ vulnerability, and the technical intricacies involved in the attacks.
Indicators of Compromise (IoCs) for DreamBus Botnet:
IP and Servers:
92[.]204.243.155: Download Serverru6r4inkaf4thlgflg4iqs5mhqwqubols5qagspvya4whp3dgbvmyhad.onion: .onion Download and Control Server
Scripts and Miners:
1d0c3e35324273ffeb434f929f834b59dcc6cdd24e9204abd32cc0abefd9f047: Bash script downloader1c49d7da416474135cd35a9166f2de0f8775f21a27cd47d28be48a2ce580d58d: XMRig Miner
DreamBus Bot Hashes:
601a2ff4a7244ed41dda1c1fc71b10d3cfefa34e2ef8ba71598f41f73c031443153b0d0916bd3150c5d4ab3e14688140b34fdd34caac725533adef8f4ab621e2e71caf456b73dade7c65662ab5cf55e02963ee3f2bfb47e5cffc1b36c0844b4d9f740c9042a7c3c03181d315d47986674c50c2fca956915318d7ca9d2a086b7f371319cd17a1ab2d3fb2c79685c3814dc24d67ced3e2f7663806e8960ff9334c21a9f094eb65256e0ea2adb5b43a85f5abfbfdf45f855daab3eb6749c6e694170a8779a427aba59a66338d85e28f007c6109c23d6b0a6bd4b251bf0f543a029f
-
🚨 #Cybersecurity Alert: DreamBus Botnet is back and exploiting a new vulnerability in RocketMQ servers (CVE-2023-33246) for remote code execution. Juniper Threat Labs reports multiple attacks installing the DreamBus malware.
Key Points:
Vulnerability Disclosure:
- In May 2023, a vulnerability (CVE-2023-33246) was disclosed that affects RocketMQ servers and allows for remote code execution.
Exploitation by DreamBus Botnet:
- Juniper Threat Labs detected multiple attacks exploiting this vulnerability to install the DreamBus bot, a malware strain last seen in 2021.
Attack Timeline:
- Attacks began in early June and peaked in mid-June.
- Attackers targeted the default port for RocketMQ (10911) and at least seven other ports.
Reconnaissance and Malicious Activities:
- Initial attacks used an open-source tool called 'interactsh' for reconnaissance.
- From June 19th, attackers began using a malicious bash script named "reketed" to download and execute payloads.
- Two methods were used for payload retrieval: TOR proxy service and a specific IP address.
Technical Details:
- The 'reketed' bash script downloads the DreamBus main module from a TOR hidden service.
- Both 'reketed' and the DreamBus main module had zero detections on VirusTotal at the time of analysis.
- The DreamBus main module is an ELF Linux binary packed with UPX, making static detection challenging.
Malware Capabilities:
- The malware can perform various functions like downloading other modules and sending notifications to the server.
- It can send requests to different paths on the TOR onion service for various actions like pinging the server, downloading and executing the main module, installing a Monero miner, and executing bash scripts.
Implications:
- The attacks add complexity to potential forensic investigations and pose a significant threat to RocketMQ servers.
The article provides a comprehensive look into the DreamBus botnet's resurgence, its exploitation of the RocketMQ vulnerability, and the technical intricacies involved in the attacks.
Indicators of Compromise (IoCs) for DreamBus Botnet:
IP and Servers:
92[.]204.243.155: Download Serverru6r4inkaf4thlgflg4iqs5mhqwqubols5qagspvya4whp3dgbvmyhad.onion: .onion Download and Control Server
Scripts and Miners:
1d0c3e35324273ffeb434f929f834b59dcc6cdd24e9204abd32cc0abefd9f047: Bash script downloader1c49d7da416474135cd35a9166f2de0f8775f21a27cd47d28be48a2ce580d58d: XMRig Miner
DreamBus Bot Hashes:
601a2ff4a7244ed41dda1c1fc71b10d3cfefa34e2ef8ba71598f41f73c031443153b0d0916bd3150c5d4ab3e14688140b34fdd34caac725533adef8f4ab621e2e71caf456b73dade7c65662ab5cf55e02963ee3f2bfb47e5cffc1b36c0844b4d9f740c9042a7c3c03181d315d47986674c50c2fca956915318d7ca9d2a086b7f371319cd17a1ab2d3fb2c79685c3814dc24d67ced3e2f7663806e8960ff9334c21a9f094eb65256e0ea2adb5b43a85f5abfbfdf45f855daab3eb6749c6e694170a8779a427aba59a66338d85e28f007c6109c23d6b0a6bd4b251bf0f543a029f
-
🔒 Critical security alert! CVE-2023-3519 affects Citrix ADC and Citrix Gateway, allowing unauthenticated remote code execution. If you're using these services, update to the latest versions ASAP. Stay safe!
The CVE-2023-3519 is a critical security vulnerability with a CVSS score of 9.8 affecting Citrix ADC and Citrix Gateway. This vulnerability allows for unauthenticated remote code execution. The appliance must be configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server for the vulnerability to be exploited.
The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities:
NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.13
NetScaler ADC and NetScaler Gateway 13.0 before 13.0-91.13
NetScaler ADC 13.1-FIPS before 13.1-37.159
NetScaler ADC 12.1-FIPS before 12.1-55.297
NetScaler ADC 12.1-NDcPP before 12.1-55.297
Citrix has observed exploits of CVE-2023-3519 on unmitigated appliances and strongly urges affected customers to install the relevant updated versions as soon as possible.[Citrix ADC and Citrix Gateway Security Bulletin](https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467)
#CyberSecurity #CVE2023-3519 #InfoSec #citrix #ADC #Gateway #RCA
-
#linux #kernelpanic #cve # This article is very well written and funny but worrying because it seems that Linux is a wee bit too complex for me. Is this not a great example of the power of open source? #cve2023 #CVE20232156 https://www.interruptlabs.co.uk/articles/linux-ipv6-route-of-death
-
#linux #kernelpanic #cve # This article is very well written and funny but worrying because it seems that Linux is a wee bit too complex for me. Is this not a great example of the power of open source? #cve2023 #CVE20232156 https://www.interruptlabs.co.uk/articles/linux-ipv6-route-of-death