ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 444 by Pierluigi Paganini

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-46604
Unauthenticated RCE in Apache ActiveMQ via OpenWire Deserialization

CVE-2023-46604 is a critical deserialization flaw (CWE-502) in the Java OpenWire protocol marshaller of Apache ActiveMQ that permits unauthenticated remote code execution (CVSS 9.8). An attacker with network access to either a Java-based OpenWire broker or client can manipulate serialized class types in the OpenWire protocol, causing the peer to instantiate arbitrary classes on the classpath and execute arbitrary shell commands. Successful exploitation yields full command execution on the target broker or client, with no authentication or user interaction required. Affected parties include anyone running ActiveMQ broker or Java client versions prior to 5.15.16, 5.16.7, 5.17.6, or 5.18.3, as well as NetApp E-Series products and Debian packages that ship affected ActiveMQ/OpenWire components. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-11-02 with known ransomware use (RansomHub), and has been used to drop Kinsing malware, Godzilla web shells, and the DripDropper implant, in some cases with attackers patching the flaw post-exploitation to lock out competing intruders.

Do: Upgrade all ActiveMQ brokers and Java OpenWire clients to 5.15.16, 5.16.7, 5.17.6, or 5.18.3 (or later), and apply the relevant NetApp E-Series and Debian updates for bundled components; restrict the OpenWire port (default TCP 61616) from untrusted networks. Hunt for indicators of the documented campaigns (Godzilla web shells, Kinsing malware, DripDropper, RansomHub) and verify the broker's current version, since attackers have been observed patching the flaw post-exploitation to hide from defenders. The CISA KEV listing means federal agencies must apply vendor mitigations or discontinue use of the product.

9.8100% KEV ransomware PoC
  • apache activemq Java-based OpenWire brokers and clients prior to 5.15.16, 5.16.7, 5.17.6, and 5.18.3
  • apache activemq legacy openwire module OpenWire marshaller as shipped in releases prior to the fixed versions 5.15.16 / 5.16.7 / 5.17.6 / 5.18.3
  • debian linux
  • +3 more
largetens of thousands of internet-exposed OpenWire brokers (order of 10,000–100,000 by public scans), plus uncounted internal deployments and bundled NetApp/Debian…
CVE-2023-46747
F5 BIG-IP TMUI Authentication Bypass Enables Unauthenticated RCE

CVE-2023-46747 is a critical authentication bypass (CVSS 9.8) in the F5 BIG-IP Configuration Utility (TMUI) affecting most BIG-IP modules, including LTM, APM, DNS, AWAF, AFM, ASM, and SSL Orchestrator. By sending undisclosed, specially crafted requests to the TMUI, an attacker with network access to the BIG-IP management port and/or self IP addresses bypasses authentication and can execute arbitrary system commands on the system. No privileges or user interaction are required, and successful exploitation effectively yields full control of the affected BIG-IP deployment. Any organization running vulnerable BIG-IP software is exposed, particularly enterprises, service providers, and government agencies whose management interface or self IPs are reachable. The flaw is being actively exploited: it was added to CISA KEV on 2023-10-31 with known ransomware use, public PoC code exists, and reporting links it to Chinese nation-state actors targeting defense and government networks.

Do: Upgrade all affected BIG-IP systems to the fixed releases identified in F5 advisory K13763 (17.1.0.1, 16.1.4, 15.1.9, 14.1.5.5, or 13.1.5.1 depending on the train, or later); the CISA KEV listing makes remediation mandatory for federal agencies. As an interim mitigation, restrict network access to the TMUI management port and self IP addresses and apply F5's documented mitigation guidance. Given active nation-state and ransomware exploitation, also audit appliances for indicators of compromise such as unexpected accounts, scheduled tasks, and configuration changes.

9.897% KEV ransomware PoC ×2
  • f5 BIG-IP Access Policy Manager
  • f5 BIG-IP Advanced Firewall Manager
  • f5 BIG-IP Advanced Web Application Firewall
  • +9 more
largetens of thousands of internet-exposed BIG-IP systems (10k-100k), with a total enterprise installed base plausibly in the hundreds of thousands
Full article388 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 05, 2023

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

Cybercrime

New Hunters International ransomware possible rebrand of Hive

Hacker Sentenced to 30 Months for SIM Swapping Conspiracy Resulting in Theft of Nearly $1 Million in Cryptocurrency

Boeing Says Its Services Division Was Hit by Cyberattack   

Hackers Accessed 632,000 Email Addresses at US Justice, Defense Departments   

Dutch hacker jailed for extortion, selling stolen data on RaidForums

US Harbors Prolific Malicious Link Shortening Service

‘Corrupt’ cop jailed for tipping off pal to EncroChat dragnet 

Malware

Ukrainian hackers disrupt internet providers in Russia-occupied territories 

BiBi-Linux: A New Wiper Dropped By Pro-Hamas Hacktivist Group  

Who killed Mozi? Finally putting the IoT zombie botnet in its grave  

AridViper, an intrusion set allegedly associated with Hamas  

WhatsApp spy mod spreads through Telegram, attacks Arabic-speaking users  

Elastic catches DPRK passing out KANDYKORN  

Hacking

The Wiki-Slack Attack  

Refresh: Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747  

Suspected Exploitation of Apache ActiveMQ CVE-2023-46604  

Unauthorized Access to Okta’s Support Case Management System: Root Cause and Remediation  

Looney Tunables Vulnerability Exploited by Kinsing  

A cascade of compromise: unveiling Lazarus’ new campaign  

Oldham Council facing 10,000 cyber attacks a day, report says

Russian Reshipping Service ‘SWAT USA Drop’ Exposed

Intelligence and Information Warfare

Fifth-Generation Warfare: AI in the Election Cycle

Minister Anand announces a ban on the use of WeChat and Kaspersky suite of applications on government mobile devices      

MuddyWater eN-Able spear-phishing with new TTPs

Russian TA499 Targets North American and European Countries     

Hackers are under investigation  

ISRAEL GAZA CONFLICT : THE CYBER PERSPECTIVE  

Cybersecurity

7th Annual Hacker Powered Security Report  

Your iPhone has a fatal security flaw — how to fix it immediately  

Internet access in Gaza partially restored after blackout

The Race to Save Our Secrets From the Computers of the Future

ODNI, Pentagon reveal FY23 intelligence budget at nearly $100 billion      

Is state intervention needed for cyber insurance?   

PSA: Your chat and call apps may leak your IP address  

German government reports risk of cyber threats higher than ever  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/153643/breaking-news/security-affairs-newsletter-round-444-by-pierluigi-paganini-international-edition.html