Chinese hackers used Pulse Secure VPN zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-22893 | Use-After-Free RCE in Ivanti Pulse Connect Secure License Services Ivanti Pulse Connect Secure, a widely deployed SSL VPN appliance, contains a use-after-free vulnerability in its license services. A remote, unauthenticated attacker can trigger the flaw via the license services and gain arbitrary code execution on the appliance, which is a high-value target because it terminates VPN sessions for enterprise networks. Any organization running an affected Pulse Connect Secure release is potentially affected; the source data does not specify exact version ranges, so administrators should compare their release against Ivanti's advisory. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and its 47.2% EPSS score (99th percentile) indicates a high likelihood of exploitation within 30 days. Do: Apply the updates per Ivanti's instructions immediately, as CISA's required action specifies. Because exploited appliances have often retained persistent webshells/backdoors even after patching, also hunt for indicators of compromise (modified appliance files, unexpected processes or accounts) and follow Ivanti's remediation guidance rather than only installing the update. Until patched, restrict or closely monitor internet access to the appliance. | 10.0 | 47% | KEV ransomware |
| largetens of thousands of internet-exposed Pulse Connect Secure VPN appliances (order of magnitude ~10^4-10^5) |
Full article552 words · extracted from therecord.media · click to collapse
Two hacking groups, including at least one confirmed Chinese cyber-espionage outfit, have used a new zero-day vulnerability in Pulse Secure VPN equipment to gain a foothold inside the networks of US defense contractors and government organizations across the world. The attacks were discovered earlier this year by cybersecurity firm FireEye and confirmed by Pulse Secure today in coordinated press releases. FireEye said the attacks began in August 2020, when the first group, which the company tracks as UNC2630 began targeting US defense contractors and European organizations. The hackers used a combination of old Pulse Secure VPN bugs, along with a new zero-day—tracked as CVE-2021-22893—, to take over Pulse Secure devices and then install one of seven malware strains (SLOWPULSE, RADIALPULSE, THINBLOOD, ATRIUM, PACEMAKER, SLIGHTPULSE, and PULSECHECK), which acted as web shells and backdoors into the hacked organization. FireEye said that UNC2630 attacks typically followed the below pattern: However, attacks against Pulse Secure devices also expanded in October 2020, when a second group, which FireEye named UNC2717, also began using the same techniques and zero-day to install their own set of malware (HARDPULSE, QUIETPULSE, and PULSEJUMP) on the networks of government agencies in Europe and the US. While FireEye couldn't formally link the two groups and hacking campaigns, the company noted the "possibility that one or more related groups is responsible for the development and dissemination of these different tools across loosely connected APT actors [state-sponsored hacking groups]." FireEye said the attacks continued until March 2021, and they also discovered two additional malware strains (bringing the total to 12) that were also used in intrusions, but which the company couldn't definitely link to a specific group. But while FireEye didn't have any information about the second group, the US security vendor said that based on internal data, UNC2630, the first group, appears to "operate on behalf of the Chinese government and may have ties to APT5," a well-known Chinese cyber-espionage group. Ivanti, the company behind the Pulse Secure VPN brand, confirmed FireEye's findings earlier today and also released a security advisory to address CVE-2021-22893. The advisory contains temporary mitigations to prevent attacks, and a final security update with a full patch will be made available in May. In addition, the company also released the Pulse Security Integrity Checker Tool, a tool that can scan Pulse Secure VPN servers for signs of compromise for CVE-2021-22893 or other previous vulnerabilities.Second group joins the fold
Pulse Secure mitigations available now, patch next month
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/chinese-hackers-use-new-pulse-secure-vpn-zero-day-to-breach-us-defense-contractors