ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 506 by Pierluigi Paganini

criticalData breach exploited in the wildimportance 60CVE-2024-43405CVE-2025-0282

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43405
Nuclei is a vulnerability scanner powered by YAML based templates.

Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature verification system could allow an attacker to bypass the signature check and possibly execute malicious code via custom code template. The vulnerability is present in the template signature verification process, specifically in the `signer` package. The vulnerability stems from a discrepancy between how the signature verification process and the YAML parser handle newline characters, combined with the way multiple signatures are processed. This allows an attacker to inject malicious content into a template while maintaining a valid signature for the benign part of the template. CLI users are affected if they execute custom code templates from unverified sources. This includes templates authored by third parties or obtained from unverified repositories. SDK Users are affected if they are developers integrating Nuclei into their platforms, particularly if they permit the execution of custom code templates by end-users. The vulnerability is addressed in Nuclei v3.3.2. Users are strongly recommended to update to this version to mitigate the security risk. As an interim measure, users should refrain from using custom templates if unable to upgrade immediately. Only trusted, verified templates should be executed. Those who are unable to upgrade Nuclei should disable running custom code templates as a workaround.

NVD description · AI analysis pending
7.81%
  • projectdiscovery nuclei
CVE-2025-0282
Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways

CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known.

Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin.

9.0100% KEV ransomware PoC ×3
  • Ivanti Connect Secure
  • Ivanti Policy Secure
  • Ivanti ZTA Gateways
largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways)
Full article417 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime  

School districts in Maine, Tennessee respond to holiday cyberattacks

The data of members of the PSA, the force that depends on Bullrich, was hacked and part of their salary was stolen  

A Day in the Life of a Prolific Voice Phishing Crew  

Phish-free PayPal Phishing  

Marijuana dispensary STIIIZY warns of leaked IDs after November data breach  

Operators of Cryptocurrency Mixers Charged with Money Laundering  

Fintech Giant Finastra Investigating Data Breach  

Telefonica Breach: Infostealer Malware Opens Door for Social Engineering Tactics  

Hackers Claim Massive Breach of Location Data Giant, Threaten to Leak Data  

Malware

Finding Malware: Unveiling PLAYFULGHOST with Google Security Operations  

EAGERBEE, with updated and novel components, targets the Middle East  

Gayfemboy: A Botnet Deliver Through a Four-Faith Industrial Router 0-day Exploit

Recruitment Phishing Scam Imitates CrowdStrike Hiring Process

Hacking

Breaking the Chain: Wiz Uncovers a Signature Verification Bypass in Nuclei, the Popular Vulnerability Scanner (CVE-2024-43405) 

Bad Likert Judge: A Novel Multi-Turn Technique to Jailbreak LLMs by Misusing Their Evaluation Capability  

Genetic Engineering Meets Reverse Engineering: DNA Sequencer’s Vulnerable BIOS

Ivanti Flaw CVE-2025-0282 Actively Exploited, Impacts Connect Secure and Policy Secure

GFI KerioControl Firewall Vulnerability Exploited in the Wild 

Samsung S24: Out of bounds write in APE Decoder 

Facebook awards researcher $100,000 for finding bug that granted internal access  

Intelligence and Information Warfare 

Chinese hack of US telecoms compromised more firms than previously known, WSJ says  

US designates Tencent as Chinese military company  

CISA Update on Treasury Breach  

Russian internet provider confirms its network was ‘destroyed’ following attack claimed by Ukrainian hackers    

Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation  

Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain  

Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases  

Cybersecurity

India Proposes Digital Data Rules with Tough Penalties and Cybersecurity Requirements

Meta is ending its fact-checking program in favor of a ‘community notes’ system similar to X  

New labels will help people pick devices less at risk of hacking 

Elon Musk says all human data for AI training ‘exhausted’ 

China releases world’s most powerful electronic warfare weapon design software – for free  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172972/breaking-news/security-affairs-newsletter-round-506-by-pierluigi-paganini-international-edition.html