Security Affairs newsletter Round 492 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-45519 | Unauthenticated Command Execution in Synacor Zimbra Collaboration Suite (ZCS) CVE-2024-45519 is an access-control weakness (CWE-284) in the postjournal service of Synacor Zimbra Collaboration Suite (ZCS) that allows an unauthenticated remote attacker to execute operating-system commands on the mail server. The postjournal service handles Zimbra's email journaling, and the flaw is reached by sending crafted mail/SMTP traffic to a vulnerable server, with no credentials or user interaction required. Successful exploitation gives the attacker command execution on the ZCS host, typically a foothold for stealing mailbox data and credentials, deploying webshells, or staging broader intrusion and ransomware activity. Any organization running ZCS is in scope, especially internet-exposed mail servers operated by enterprises, hosting/ISP providers, education, and government. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2024-10-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile), though no public PoC is known. Do: Upgrade ZCS to the latest patch release per Synacor's advisory for this CVE, prioritizing internet-facing mail servers, since CISA's KEV required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. If patching cannot be done immediately, restrict untrusted network access to the postjournal/SMTP path and treat the host as presumptively compromised because exploitation is already in the wild. Check postjournal logs and unexpected child processes or dropped files on the server for signs of compromise, and re-verify after patching. | 9.8 | 100% | KEV PoC |
| largetens of thousands of internet-exposed Zimbra mail servers (roughly 30,000-50,000 per public internet scans), plus many more firewalled deployments |
Full article823 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
October 06, 2024

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Cybercrime
U.K. National Charged with Multimillion-Dollar Hack-to-Trade Fraud Scheme
Crooked Cops, Stolen Laptops & the Ghost of UGNazi
Investigating Infrastructure and Tactics of Phishing-as-a-Service Platform Sniper Dz
Police arrest four suspects linked to LockBit ransomware gang
How the FBI and Mandiant caught a ‘serial hacker’ who tried to fake his own death
FIN7 hosting honeypot domains with malicious AI DeepNude Generators – New Silent Push research
Arrests in international operation targeting cybercriminals in West Africa
A Single Cloud Compromise Can Feed an Army of AI Sex Bots
Pig Butchering Alert: Fraudulent Trading App targeted iOS and Android users
Fraudsters imprisoned for scamming Apple out of 6,000 iPhones
Malware
Rhadamanthys Stealer Adds Innovative AI Feature in Version 0.7.0
Threat Actors leverage Docker Swarm and Kubernetes to mine cryptocurrency at scale
Crypto-Stealing Code Lurking in Python Package Dependencies
Fake browser updates spread updated WarmCookie malware
Hacking
Demystifying Physical Memory Primitive Exploitation on Windows
Trojan cars: Why the US fears Chinese cyberattacks on electric vehicles
Zimbra – Remote Command Execution (CVE-2024-45519)
Critical Zimbra Vulnerability Exploited One Day After PoC Release
Zero-Day Breach at Rackspace Sparks Vendor Blame Game
Thousands of Adobe Commerce stores hacked in competing CosmicSting campaigns
Unauthenticated Stored XSS Vulnerability in LiteSpeed Cache Plugin Affecting 6+ Million Sites
Intelligence and Information Warfare
Israel reportedly hacks Beirut airport control tower, warns Iranian plane not to land
FSB Center for Special Technologies (TsST): Crafting Russia’s Cyber Weapons for Information Warfare
North Korean hackers targeted arms company Diehl
Chinese Military Exploring Wasy to Win in Intelligent Warfare Amidst Change & Constancy
North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks
Dutch government blames a ‘state actor’ for hacking a police network
Justice Department Disrupts Russian Intelligence Spear-Phishing Efforts
Deep Dive into North Korea’s Ongoing Campaign Against Southeast Asia
Separating the bee from the panda: CeranaKeeper making a beeline for Thailand
Cybersecurity
Endpoint Prevention and Response (EPR) Test findings
Critical Flaws in Tank Gauge Systems Expose Gas Stations to Remote Attacks
Media giant AFP hit by cyberattack impacting news delivery services
SecurityCracking the Cloud: The Persistent Threat of Credential-Based Attacks
Fake memories, persistent threats: When AI remembers what isn’t true
Telegram Confirms it Gave U.S. User Data to the Cops
First Ai-iD Kit toolkit built to empower and educate everyone about deepfakes
How Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack
Protecting Democratic Institutions from Cyber Threats
Finding a needle in a haystack: Machine learning at the forefront of threat hunting research
German-French recommendations for the use of AI programming assistants
Pixel’s Proactive Approach to Security: Addressing Vulnerabilities in Cellular Modems
Subscribe to the newsletter for free here:
https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7093942975545667584
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs –hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/169417/breaking-news/security-affairs-newsletter-round-492-by-pierluigi-paganini-international-edition.html