Cybersecurity experts warn of new vulnerabilities affecting Apple, Atlassian and Fortra products
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-22527 | Unauthenticated OGNL Template Injection RCE in Atlassian Confluence Data Center/Server Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability (CWE-74) in which attacker-controlled input is evaluated by the application as an OGNL expression. A remote, unauthenticated attacker can trigger the flaw by sending a crafted HTTP request that injects OGNL expressions, which the server then executes. Successful exploitation leads to remote code execution on the host running Confluence, giving the attacker control of the system without any credentials. Any organization running self-hosted Confluence Data Center or Server is potentially affected — the available data does not specify version ranges, so operators should consult Atlassian's advisory — with internet-facing instances at highest risk. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-24 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile). Do: Patch to the fixed release specified in Atlassian's advisory immediately, prioritizing internet-exposed instances, since the flaw is in CISA's KEV with known ransomware use and carries a 100% EPSS. If patching is not immediately possible, apply the vendor's mitigations per the KEV required action — or discontinue/restrict use — for example by limiting unauthenticated access to Confluence from the internet. Review Confluence access and application logs for anomalous unauthenticated requests and indicators of command execution or ransomware activity. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed Confluence instances (order of 10,000–100,000) | |
| CVE-2023-34048 | Unauthenticated Out-of-Bounds Write RCE in VMware vCenter Server VMware vCenter Server contains an out-of-bounds write vulnerability (CWE-787) in its implementation of the DCERPC protocol. A remote, unauthenticated attacker with network access to vCenter Server can send crafted DCERPC traffic that corrupts memory, potentially leading to remote code execution on the vCenter appliance. Because vCenter is the central management plane for VMware vSphere environments, full compromise of it hands attackers a high-value foothold for lateral movement, consistent with the critical 9.8 CVSS score. Any organization running an affected VMware vCenter Server release is exposed (exact version ranges per VMware's advisory, including VMware Cloud Foundation deployments that bundle vCenter). Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-01-22, a public PoC is available, news reports describe China-linked APT UNC3886 exploiting it as a zero-day, and EPSS estimates a 99.4% probability of exploitation within 30 days. Do: Immediately upgrade vCenter Server — and VMware Cloud Foundation deployments that bundle it — to the patched builds identified in VMware's advisory, prioritizing internet-facing instances; if patching must wait, restrict network access to the vCenter management interface as the CISA KEV required action permits. Because exploitation is confirmed in the wild including by an APT, also hunt for signs of compromise such as unexpected processes or authentication activity on vCenter hosts and managed ESXi estate. | 9.8 | 99% | KEV PoC |
| mass≈100,000+ vCenter Server deployments globally (tens of thousands directly internet-exposed per public scans, far more reachable on internal networks) | |
| CVE-2023-46604 | Unauthenticated RCE in Apache ActiveMQ via OpenWire Deserialization CVE-2023-46604 is a critical deserialization flaw (CWE-502) in the Java OpenWire protocol marshaller of Apache ActiveMQ that permits unauthenticated remote code execution (CVSS 9.8). An attacker with network access to either a Java-based OpenWire broker or client can manipulate serialized class types in the OpenWire protocol, causing the peer to instantiate arbitrary classes on the classpath and execute arbitrary shell commands. Successful exploitation yields full command execution on the target broker or client, with no authentication or user interaction required. Affected parties include anyone running ActiveMQ broker or Java client versions prior to 5.15.16, 5.16.7, 5.17.6, or 5.18.3, as well as NetApp E-Series products and Debian packages that ship affected ActiveMQ/OpenWire components. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-11-02 with known ransomware use (RansomHub), and has been used to drop Kinsing malware, Godzilla web shells, and the DripDropper implant, in some cases with attackers patching the flaw post-exploitation to lock out competing intruders. Do: Upgrade all ActiveMQ brokers and Java OpenWire clients to 5.15.16, 5.16.7, 5.17.6, or 5.18.3 (or later), and apply the relevant NetApp E-Series and Debian updates for bundled components; restrict the OpenWire port (default TCP 61616) from untrusted networks. Hunt for indicators of the documented campaigns (Godzilla web shells, Kinsing malware, DripDropper, RansomHub) and verify the broker's current version, since attackers have been observed patching the flaw post-exploitation to hide from defenders. The CISA KEV listing means federal agencies must apply vendor mitigations or discontinue use of the product. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed OpenWire brokers (order of 10,000–100,000 by public scans), plus uncounted internal deployments and bundled NetApp/Debian… | |
| CVE-2024-0204 | Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal. Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal. NVD description · AI analysis pending | 9.8 | 95% |
| — | ||
| CVE-2024-23222 | Apple WebKit Type Confusion Enables Arbitrary Code Execution Across iOS, macOS, tvOS CVE-2024-23222 is a type confusion flaw (CWE-843) in Apple's WebKit engine that allows arbitrary code execution when a device processes maliciously crafted web content, for example when a user is lured into loading attacker-controlled web pages in Safari or another WebKit-based view (the CVSS vector confirms user interaction is required). It affects a broad slice of the Apple ecosystem: Safari, iPhone OS/iPadOS on the iOS 15, 16 and 17 branches, macOS Monterey/Ventura/Sonoma, tvOS and visionOS, prior to the January 22, 2024 fixes. A successful attacker gains code execution on the target device with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8). The flaw was fixed in Safari 17.3, iOS/iPadOS 17.3, and backported to iOS/iPadOS 15.8.7 and 16.7.5 for devices that cannot upgrade to iOS 17, plus macOS Monterey 12.7.3, Ventura 13.6.4, Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Exploitation is confirmed in the wild: the vulnerability was added to CISA KEV on 2024-01-23, one day after the fixes shipped, and is associated with the Coruna exploit kit, which reportedly chains multiple exploits to target iOS devices including older versions. Do: Update all affected devices to Safari 17.3, iOS/iPadOS 17.3 (or the iOS/iPadOS 15.8.7 and 16.7.5 backports for devices that cannot run 17), macOS Monterey 12.7.3, macOS Ventura 13.6.4, macOS Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Prioritize endpoints used for web browsing and mobile users, since exploitation only requires a user to process crafted web content. The CISA KEV listing (added 2024-01-23) makes applying these vendor updates mandatory under the KEV required action, so verify fleet versions and confirm no devices remain on pre-patch builds. | 8.8 | 11% | KEV |
| massover 1 billion active Apple devices (effectively Apple's entire unpatched iPhone/iPad/Mac/Apple TV fleet) |
Full article787 words · extracted from therecord.media · click to collapse
Multiple new vulnerabilities are being exploited by hackers in recent days, prompting alarm from experts worried about how they will be used by cybercriminals and nation states. Over the last week, vulnerabilities affecting tech giants including Apple, VMware, Atlassian, Fortra, Apache and others have been highlighted both by cybersecurity experts and government agencies like the Cybersecurity and Infrastructure Security Agency (CISA). On Tuesday, CISA echoed warnings from Apple that CVE-2024-23222 — a vulnerability affecting several versions of iPhones and iPads — is being exploited by cybercriminals. The vulnerability is the first zero-day announced by Apple in 2024 — the company patched 20 zero-days last year. The bug allows hackers to execute code on a victim’s device. “Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited,” Apple said on Tuesday. CISA ordered all federal civilian agencies to patch the bug by February 13. That order came on the same day that cybersecurity researchers raised alarms about the latest vulnerability affecting Fortra’s GoAnywhere file transfer software, which was at the center of controversy last year when a Russian ransomware gang used a different issue with the tool to attack dozens of companies and governments. In an advisory published on Monday, Fortra said CVE-2024-0204 was discovered in December and allows an attacker to create an admin user account through the administration portal — giving them widespread access to a victim’s system. The company urged customers to patch the vulnerability and noted that it carries a 9.8 CVSS severity score, indicating that it is a critical vulnerability. In a statement to Recorded Future News, the company said they “have no reports of active exploitation in the wild regarding this CVE.” They also shared a letter that was sent to customers in December warning about the vulnerability and providing detailed guidance about how customers can resolve the issue. Hackers were recently revealed to be actively attacking two vulnerabilities affecting products from Atlassian and Apache. Researchers at Greynoise observed steep spikes in attempts to exploit CVE-2023-22527 — a vulnerability Atlassian announced last week that affects Confluence Data Center and Confluence Servers. Atlassian said the vulnerability carries the highest possible severity score of 10 and urged customers to patch it as soon as possible. Experts at Shadowserver said they have seen over 600 different IP addresses attempting to exploit the more than 11,000 instances that are exposed to the internet. Cyber defenders raised similar concerns with a relatively old vulnerability affecting Apache products that cybercriminals began exploiting this weekend. According to findings from cybersecurity firm Trustwave, a surge in attacks exploiting CVE-2023-46604 in Apache ActiveMQ hosts. Apache ActiveMQ is widely-used software that helps applications communicate with each other and share data. “Since a proof of concept of the exploit was made publicly available in October 2023, threat actors have been using it to deploy crypto-miners, rootkits, ransomware, and remote access trojans,” the company said in a blog post. CISA said the vulnerability was exploited as far back as November and forced all federal civilian agencies to address the issue by November 23. Incident responders at the time reported that hackers using the HelloKitty ransomware were behind a campaign to exploit CVE-2023-46604. In the latest campaign outlined by Trustwave, hackers are using the bug to infiltrate systems and deploy tools that allow them to fully control a system. Another popular tool is facing attacks this week, according to CISA and incident responders at Google-owned cybersecurity firm Mandiant. Mandiant warned last week that an espionage group tied to the Chinese government has been exploiting CVE-2023-34048 — an issue affecting VMware vCenter Servers. The vulnerability was disclosed in October but VMware updated the advisory last Wednesday to confirm that it was seeing exploitation attempts. Mandiant said that in its investigation of the issue, it discovered Chinese espionage hackers have been exploiting it as far back as 2021. The company said the hackers had a window of about a year and a half to exploit the issue before VMware became aware of it. Researchers at Censys said they have seen hundreds of systems that may be vulnerable to the issue. CISA added the bug to its Known Exploited Vulnerabilities catalog on Monday, giving federal civilian agencies until February 12 to patch it.Atlassian and Apache attacks
Mandiant and CISA warn of VMware attacks
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cybersecurity-experts-warn-of-vulnerabilities-apple-atlassian-fortra