THN Recap: Top Cybersecurity Threats, Tools, and Practices (Nov 18
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-0012 +1 in the same advisory: …9474 | Authentication Bypass in Palo Alto Networks PAN-OS Management Interface CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474. Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device. | 9.3 group max | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised | |
| CVE-2024-0138 | NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2024-10217 +1 in the same advisory: …10218 | XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational Intelligence XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational Intelligence NVD description · AI analysis pending | 9.2 | <1% | — | — | ||
| CVE-2024-10224 | Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary s Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval(). NVD description · AI analysis pending | 7.8 | 9% | PoC ×3 |
| — | |
| CVE-2024-10524 | Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host. NVD description · AI analysis pending | 6.5 | 1% | — | — | ||
| CVE-2024-48990 | Local Privilege Escalation in Ubuntu needrestart via attacker-controlled PYTHONPATH CVE-2024-48990 is an uncontrolled search path flaw (CWE-427) in needrestart, the tool used on Ubuntu and Debian systems to check which services need restarting, affecting all versions before 3.8. A local attacker with low privileges can set the PYTHONPATH environment variable so that when needrestart executes the Python interpreter with root privileges, the attacker's code is loaded and run as root. Successful exploitation yields arbitrary code execution as root, giving the attacker full control of the affected machine. Any server, workstation, or container image running needrestart prior to 3.8 — most notably Ubuntu systems, where the package is shipped and maintained — is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known yet, though EPSS assigns an elevated 20.5% probability of exploitation within 30 days (97th percentile). Do: Upgrade needrestart to version 3.8 or later using your distribution's security updates (Ubuntu packages are issued by the Ubuntu security team). Administrators should audit installed systems (e.g., check the needrestart package version) and, as an interim mitigation, restrict local unprivileged access and be cautious running needrestart in environments where users can control environment variables. Given the elevated EPSS score, prioritize patching multi-user servers where local accounts or untrusted code can run. | 7.8 | 20% |
| masswell over 1,000,000 installations; plausibly tens of millions of systems | ||
| CVE-2024-34719 | In multiple locations, there is a possible permissions bypass due to a missing null check. In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2024-44308 +1 in the same advisory: …44309 | Arbitrary Code Execution via Crafted Web Content in Apple Safari, iOS, macOS and visionOS CVE-2024-44308 is a code execution vulnerability in the web content processing engine used by Safari and Apple's operating systems, which Apple addressed with improved checks in emergency updates released in November 2024. It is triggered when a device processes maliciously crafted web content, for example when a user is lured to an attacker-controlled webpage, and requires user interaction (CVSS 3.1: AV:N/UI:R). Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Users of Safari before 18.1.1, iOS and iPadOS before 17.7.2 and 18.1.1, macOS Sequoia before 15.1.1, and visionOS before 2.1.1 are affected; Debian Linux is also listed in the CPE data but no Debian-specific fix version was provided in the source. Apple reported active exploitation, specifically on Intel-based Mac systems, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-21; EPSS assigns a 9.4% probability of exploitation within 30 days. Do: Immediately update to Safari 18.1.1, iOS/iPadOS 17.7.2 or 18.1.1, macOS Sequoia 15.1.1 and visionOS 2.1.1, prioritizing Intel-based Macs since confirmed exploitation was reported on those systems. Federal agencies must patch per CISA's KEV requirement (added 2024-11-21), and defenders should review unpatched Macs for signs of browser-based compromise. Debian users should monitor their vendor's advisory for a WebKit-related backport, as no fixed Debian version was specified in the source data. | 8.8 group max | 10% | KEV |
| masshundreds of millions to 1 billion+ users (Apple's global active device base across iPhone, iPad, Mac, Vision Pro and Safari) | |
| CVE-2024-50306 | Unchecked return value can allow Apache Traffic Server to retain privileges on startup. Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 through 10.0.1. Users are recommended to upgrade to version 9.2.6 or 10.0.2, which fixes the issue. NVD description · AI analysis pending | 9.1 | 2% |
| — | ||
| CVE-2024-51092 | LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController. LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory(). NVD description · AI analysis pending | 9.1 | 7% | PoC ×2 |
| — | |
| CVE-2024-52034 | An OS Command Injection vulnerability exists within myPRO Manager. An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands. NVD description · AI analysis pending | 10.0 | 2% | — | — | ||
| CVE-2024-9942 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. NVD description · AI analysis pending | 9.8 | 1% |
| — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | bing.com | n attacker to render a specially-crafted map within the www.bing[.]com context and trigger code execution by bypassing a Keyhole |
Full article2,548 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 25, 2024Cybersecurity / Critical Updates
We hear terms like “state-sponsored attacks” and “critical vulnerabilities” all the time, but what’s really going on behind those words? This week’s cybersecurity news isn’t just about hackers and headlines—it’s about how digital risks shape our lives in ways we might not even realize.
For instance, telecom networks being breached isn’t just about stolen data—it’s about power. Hackers are positioning themselves to control the networks we rely on for everything, from making calls to running businesses. And those techy-sounding CVEs? They’re not just random numbers; they’re like ticking time bombs in the software you use every day, from your phone to your work tools.
These stories aren’t just for the experts—they’re for all of us. They show how easily the digital world we trust can be turned against us. But they also show us the power of staying informed and prepared. Dive into this week’s recap, and let’s uncover the risks, the solutions, and the small steps we can all take to stay ahead in a world that’s moving faster than ever. You don’t need to be a cybersecurity pro to care—just someone who wants to understand the bigger picture. Let’s explore it together!
⚡ Threat of the Week
New Liminal Panda Group Goes After the Telecom Sector: A previously undocumented China-nexus cyber espionage group, Liminal Panda, has orchestrated a series of targeted cyber attacks on telecom entities in South Asia and Africa since 2020. Using sophisticated tools like SIGTRANslator and CordScan, the group exploits weak passwords and telecom protocols to harvest mobile subscriber data, call metadata, and SMS messages. This development coincides with U.S. telecom providers, including AT&T, Verizon, T-Mobile, and Lumen Technologies, becoming targets of another China-linked hacking group, Salt Typhoon. The U.S. Cyber Command has stated that these efforts aim to establish footholds in critical U.S. infrastructure IT networks, potentially preparing for a major clash with the U.S.
🔔 Top News
- Palo Alto Networks Flaws Exploited to Compromise About 2,000 Devices: The newly disclosed security flaws impacting Palo Alto Networks firewalls – CVE-2024-0012 (CVSS score: 9.3) and CVE-2024-9474 (CVSS score: 6.9) – have been exploited to breach roughly 2,000 devices across the world. These vulnerabilities could allow an attacker to bypass authentication and escalate their privileges to perform various malicious actions, including executing arbitrary code. The network security vendor told The Hacker News that the number "represents less than half of one percent of all Palo Alto Networks firewalls deployed globally that remain potentially unpatched." The company also said it had been proactively sharing information since November 8, 2024, urging customers to secure their device management interfaces and mitigate potential threats. The guidance, it added, has been effective in mitigating threat activity to a great extent.
- 5 Alleged Scattered Spider Members Charged: The U.S. unsealed charges against five members of the infamous Scattered Spider cybercrime crew, including a U.K. national, for their role in orchestrating social engineering attacks between September 2021 to April 2023 to steal credentials and siphon funds from cryptocurrency wallets. If convicted, each of the U.S.-based defendants face up to 27 years in prison for all the charges.
- Ngioweb Botnet Malware Fuels NSOCKS Proxy Service: The malware known as Ngioweb has been used to fuel a notorious residential proxy service called NSOCKS, as well as other services such as VN5Socks and Shopsocks5. The attacks primarily target vulnerable IoT devices from various vendors like NETGEAR, Uniview, Reolink, Zyxel, Comtrend, SmartRG, Linear Emerge, Hikvision, and NUUO, using automated scripts in order to deploy the Ngioweb malware.
- Russian Threat Actors Unleash Attacks Against Central Asia: A Russian threat activity cluster dubbed TAG-110 has primarily targeted entities in Central Asia, and to a lesser extent East Asia and Europe, as part of a broad campaign that deploys malware known as HATVIBE and CHERRYSPY for information gathering and exfiltration purposes. TAG-110 is assessed to be affiliated with a Russian state-sponsored hacking group called APT28.
- North Korea's IT Worker Scheme's Chinese Links Uncovered: A new analysis has revealed that the fake IT consulting firms set up North Korean threat actors to secure jobs at companies in the U.S. and abroad are part of a broader, active network of front companies originating from China. In these schemes, the IT workers who land employment under forged identities have been observed funneling their income back to North Korea through the use of online payment services and Chinese bank accounts.
- Cybercriminals Use Ghost Tap Method for Cash-Out: A legitimate near-field communication (NFC) research tool called NFCGate is being abused by cybercriminals to cash out funds from victim's bank accounts via point-of-sale (PoS) terminals. One crucial caveat here is that the attack hinges on the threat actors previously compromising a device and installing some sort of a banking malware that can capture credentials and two-factor authentication (2FA) codes.
️🔥 Trending CVEs
Recent cybersecurity developments have highlighted several critical vulnerabilities, including: CVE-2024-44308, CVE-2024-44309 (Apple), CVE-2024-48990, CVE-2024-48991, CVE-2024-48992, CVE-2024-11003, CVE-2024-10224 (needrestart), CVE-2024-51092 (LibreNMS), CVE-2024-10217, CVE-2024-10218 (TIBCO), CVE-2024-50306 (Apache Traffic Server), CVE-2024-10524 (wget), CVE-2024-34719 (Android), CVE-2024-9942 (WPGYM), CVE-2024-52034 (mySCADA myPRO), and CVE-2024-0138 (NVIDIA). These security flaws are serious and could put both companies and regular people at risk.
📰 Around the Cyber World
- A New Way to outsmart Fortinet's Logging Mechanism: Thanks to a quirk in Fortinet VPN server's logging mechanism, which only captures failed login events during authentication attempts against the server, a malicious attacker could conceal the successful verification of credentials during a brute-force attack without tipping off incident response (IR) teams of compromised logins. While a log entry for the successful login is created during the authorization phase, the attacker could devise a method that stops at the authentication step, and confirm if the credentials are legitimate. "This discovery was surprising, as it indicated that IR teams monitoring Fortinet VPN usage, cannot differentiate between a failed and a successful brute-force attempt," Pentera said. "This means that if an attacker were to use the technique we discovered, the successful login could go undetected, potentially leaving their network compromised."
- Cross-Site Scripting (XSS) Flaw Uncovered in Bing: A newly disclosed XSS flaw in Microsoft Bing could have been abused to execute arbitrary code in the context of the website by taking advantage of an API endpoint in Bing Maps Dev Center Portal. This could allow an attacker to render a specially-crafted map within the www.bing[.]com context and trigger code execution by bypassing a Keyhole Markup Language (KML) HTML/XSS blocklist. Following responsible disclosure on August 26, 2024, the issue was addressed by Microsoft as of September 30.
- CWE Top 25 Most Dangerous Software Weaknesses for 2024 Released: Speaking of XSS flaws, the vulnerability class has topped the list of top 25 Dangerous Software Weaknesses compiled by MITRE based on an analysis of 31,770 Common Vulnerabilities and Exposures (CVE) records from the 2024 dataset. Out-of-bounds writes, SQL injections, Cross-Site Request Forgery (CSRF) flaws, and path traversal bugs round up the remaining four spots. "Uncovering the root causes of these vulnerabilities serves as a powerful guide for investments, policies, and practices to prevent these vulnerabilities from occurring in the first place — benefiting both industry and government stakeholders," MITRE said.
- Millions of Data Records Exposed Due to Power Pages Misconfigurations: Missing or misconfigured access controls in websites built with Microsoft Power Pages are exposing private organizations and government entities' sensitive data to outside parties, including full names, email addresses, phone numbers, and home addresses, leading to potential breaches. "These data exposures are occurring due to a misunderstanding of access controls within Power Pages, and insecure custom code implementations," AppOmni said. "By granting unauthenticated users excessive permissions, anyone may have the ability to extract records from the database using readily-available Power Page APIs." What's more, some sites have been found to grant even anonymous users "global access" to read data from database tables and fail to implement masking for sensitive data.
- Meta Fined $25.4 million in India Over 2021 WhatsApp Privacy Policy: India's competition watchdog, the Competition Commission of India (CCI), slapped Meta with a five-year ban on sharing information collected from WhatsApp with sister platforms Facebook and Instagram for advertising purposes. It also levied a fine of ₹213.14 crore (about $25.3 million) for antitrust violations stemming from the controversial 2021 privacy policy update, stating the updated privacy policy is an abuse of dominant position by the social media giant. The policy update, as revealed by The Hacker News in early January 2021, sought users' agreement to broader data collection and sharing with no option to refuse the changes. "The policy update, which compelled users to accept expanded data collection and sharing within the Meta group on a 'take-it-or-leave-it' basis, violated user autonomy by offering no opt-out option," the Internet Freedom Foundation (IFF) said. "The ruling reinforces the need for greater accountability from tech giants, ensuring that users' rights are protected, and the principles of fair competition are upheld in digital markets." Meta said it disagrees with the ruling, and that it intends to challenge CCI's decision.
- Alleged Russian Phobos ransomware administrator extradited to U.S.: A 42-year-old Russian national, Evgenii Ptitsyn (aka derxan and zimmermanx), has been extradited from South Korea to the U.S. to face charges related to the sale, distribution, and operation of Phobos ransomware since at least November 2020. Ptitsyn, who is alleged to be an administrator, has been charged in a 13-count indictment with wire fraud conspiracy, wire fraud, conspiracy to commit computer fraud and abuse, four counts of causing intentional damage to protected computers, and four counts of extortion in relation to hacking. More than 1,000 public and private entities in the U.S. and around the world are estimated to have been victimized by the ransomware group, earning them more than $16 million dollars in extorted ransom payments. Ptitsyn and his co-conspirators have been accused of advertising the Phobos ransomware for free through posts on cybercrime forums, and charging their affiliates around $300 to receive the decryption key to access the data. Describing it as a "lower-profile but highly impactful threat," Trellix said, "Phobos' approach focused on volume rather than high-profile targets, allowing it to maintain a steady stream of victims while remaining relatively under the radar." It also helped that the ransomware operation lacked a dedicated data leak site, enabling it to avoid drawing the attention of law enforcement and cybersecurity researchers.
- Jailbreaking LLM-Controlled Robots: New research from a group of academics from the University of Pennsylvania has found that it's possible to jailbreak large language models (LLMs) used in robotics, causing them to ignore their safeguards and elicit harmful physical damage in the real world. The attacks, dubbed RoboPAIR, have been successfully demonstrated against "a self-driving LLM, a wheeled academic robot, and, most concerningly, the Unitree Go2 robot dog, which is actively deployed in war zones and by law enforcement," security researcher Alex Robey said. "Although defenses have shown promise against attacks on chatbots, these algorithms may not generalize to robotic settings, in which tasks are context-dependent and failure constitutes physical harm."
🎥 Expert Webinar
- 🤖 Building Secure AI Apps—No More Guesswork — AI is taking the world by storm, but are your apps ready for the risks? Whether it’s guarding against data leaks or preventing costly operational chaos, we’ve got you covered. In this webinar, we’ll show you how to bake security right into your AI apps, protect your data, and dodge common pitfalls. You’ll walk away with practical tips and tools to keep your AI projects safe and sound. Ready to future-proof your development game? Save your spot today!
- 🔑 Protect What Matters Most: Master Privileged Access Security — Privileged accounts are prime targets for cyberattacks, and traditional PAM solutions often leave critical gaps. Join our webinar to uncover blind spots, gain full visibility, enforce least privilege and Just-in-Time policies, and secure your organization against evolving threats. Strengthen your defenses—register now!
- 🚀 Master Certificate Replacement Without the Headache — Is replacing revoked certificates a total nightmare for your team? It doesn’t have to be! Join our free webinar and learn how to swap out certificates like a pro—fast, efficient, and stress-free. We’ll reveal how to cut downtime to almost zero, automate the entire process, stay ahead with crypto agility, and lock in best practices that’ll keep your systems rock-solid. Don’t let certificates slow you down—get the know-how to speed things up!
🔧 Cybersecurity Tools
- Halberd: Multi-Cloud Security Testing Tool — Halberd is an open-source tool for easy, proactive cloud security testing across Entra ID, M365, Azure, and AWS. With a sleek web interface, it lets you simulate real-world attacks, validate defenses, and generate actionable insights—all at lightning speed. From attack playbooks to detailed reports and smart dashboards, Halberd makes tackling cloud misconfigurations a breeze.
- BlindBrute: Your Go-To Tool for Blind SQL Injection — BlindBrute is a powerful and flexible Python tool designed to simplify blind SQL injection attacks. It detects vulnerabilities using status codes, content length, keywords, or time-based methods and adapts to various scenarios with customizable payloads. With features like database and column detection, data length discovery, and multiple extraction methods (character-by-character, binary search, or dictionary attack), BlindBrute ensures efficient data retrieval. Plus, it supports multithreading, customizable HTTP requests, and all major HTTP methods, making it a versatile solution for tackling complex SQL injection tasks with ease.
🔒 Tip of the Week
Neutralize Threats with DNS Sinkholing — Ever wish you could cut off malware and phishing attacks before they even reach your systems? That’s exactly what DNS sinkholing does—and it’s simpler than you think. By redirecting traffic headed to known malicious domains (used by botnets, phishing, or malware) to a “sinkhole” IP, this technique blocks threats right at the source. All you need is a DNS server, a feed of real-time threat data from sources like Spamhaus or OpenPhish, and a controlled sinkhole server to stop bad actors in their tracks.
But here’s the kicker: DNS sinkholing doesn’t just block threats—it’s a detective, too. When infected devices try to reach sinkholed domains, their activity gets logged, giving you a clear view of which endpoints are compromised. This means you can pinpoint the issue, isolate the infected devices, and fix the problem before it spirals out of control. Want to take it a step further? You can even set it up to alert users when threats are blocked, raising awareness and curbing risky behavior.
The best part? Pair DNS sinkholing with automated tools like SIEM systems, and you’ll get instant alerts, detailed threat reports, and a real-time look at your network security. It’s low-cost, high-impact, and incredibly effective—a modern, proactive way to turn your DNS into your first line of defense. Ready to level up your threat management game? DNS sinkholing is the tool you didn’t know you needed.
Conclusion
This week’s news shows us one thing loud and clear: the digital world is a battleground, and everything we use—our phones, apps, and networks—is in the crossfire. But don’t worry, you don’t need to be a cybersecurity expert to make a difference.
Staying sharp about threats, questioning how secure your tools really are, and doing simple things like keeping software updated and using strong passwords can go a long way.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/11/thn-recap-top-cybersecurity-threats_25.html