LockBit ransomware gang leaked data stolen from Boeing
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-4966 | Info-Disclosure Buffer Overflow (CitrixBleed) in Citrix NetScaler ADC/Gateway Citrix NetScaler ADC and NetScaler Gateway appliances contain a buffer overflow (CWE-119) that leaks sensitive information from device memory when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote attacker who can reach such a configuration can trigger the overflow and read memory contents, harvesting sensitive data such as session tokens (a technique that enables session hijacking which can bypass multi-factor authentication). Any organization running an affected NetScaler ADC or Gateway appliance in these configurations is exposed, with appliances deployed as VPN or access gateways being the primary concern. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2023-10-18 with known ransomware use and a 100% EPSS exploitation probability, although no public proof-of-concept is known at this time. Because tokens stolen from memory can remain valid even after patching, responders must terminate all active and persistent sessions as part of remediation. Do: Upgrade affected appliances to the patched builds cited in Citrix's advisory, then immediately kill all active and persistent ICA/AAA sessions per the vendor instructions, since patching alone does not invalidate session tokens attackers may have already stolen. If patching is not immediately possible, discontinue use of the affected Gateway/AAA configurations as CISA directs. Given known ransomware abuse, also hunt for signs of exploitation such as logins from unexpected sources, anomalous session reuse, or suspicious mailbox changes, and reset credentials for potentially exposed accounts. | 7.5 | 100% | KEV ransomware |
| masshundreds of thousands of internet-exposed NetScaler ADC/Gateway appliances (public internet scan counts), plus an unknown number of VPN-only or internal… |
Full article460 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 13, 2023

The LockBit ransomware group published data allegedly stolen from the aerospace giant Boeing in a recent attack.
The Boeing Company, commonly known as Boeing, is one of the world’s largest aerospace manufacturers and defense contractors.
In 2022, Boeing recorded $66.61 billion in sales, the aerospace giant has 156,000 (2022).
At the end of October, the Lockbit ransomware group added Boeing to the list of victims on its Tor leak site. The gang claims to have stolen a huge amount of sensitive data from the company and threatens to publish it if Boeing does not contact them within the initial deadline (02 Nov, 2023 13:25:39 UTC, later postponed to 10 Nov, 2023).

In early November 2023, the company confirmed that its services division was hit by a cyber attack, it also added that the investigation is still ongoing. The attack targeted elements of the parts and distribution business run by its global services division.
Boeing notifies law enforcement agencies and relevant regulatory authorities.
“We are actively investigating the incident and coordinating with law enforcement and regulatory authorities.” reads the statement released by the aerospace giant. “A cyber gang with Russian ties, known as Lockbit, claimed in a post on the dark web last week that it would start releasing “sensitive data” if the aerospace and defense giant didn’t meet a ransom demand by Nov. 2. But on Wednesday evening, there was no mention of Boeing on Lockbit’s leak website.”
Boeing refused to pay the ransom and the LockBit group leaked more than 40GB of files from Boeing.
Bleeping Computer analyzed the leaked data and reported that most of the published data are backups for various systems. Most recent documents in the leaked data are dated back to October 22.
At this time, it’s unclear how threat actors have breached the company. Some experts speculate attackers may have carried out the ‘Citrix Bleed‘ attack to breach the company.
In October, Citrix urged administrators to secure all NetScaler ADC and Gateway appliances against the CVE-2023-4966 vulnerability, which is actively exploited in attacks.
On October 10, Citrix published a security bulletin related to a critical vulnerability, tracked as CVE-2023-4966, in Citrix NetScaler ADC/Gateway devices.
Researchers from Mandiant observed the exploitation of this vulnerability as a zero-day since late August.
Threat actors exploited this vulnerability to hijack existing authenticated sessions and bypass multifactor authentication or other strong authentication requirements. The researchers warn that these sessions may persist after the update to mitigate CVE-2023-4966 has been deployed.
Mandiant also observed threat actors hijacking sessions where session data was stolen prior to the patch deployment and subsequently used by the threat actor.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, North Korea)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/154115/cyber-crime/lockbit-ransomware-leaked-boeing-data.html