ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-13379
Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN

CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors.

Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible.

9.8100% KEV ransomware
  • Fortinet FortiOS
mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices)
CVE-2019-10068
Unauthenticated RCE in Kentico Xperience Staging Service

CVE-2019-10068 is a .NET deserialization flaw (CWE-502) in the Kentico Xperience staging service that stems from a failure to validate security headers on incoming requests. Because of this, a specially crafted request can bypass the staging service's initial authentication and reach the deserialization routine with attacker-controlled .NET object data. Successful exploitation yields unauthenticated remote code execution on the server hosting the Kentico instance, with full confidentiality, integrity, and availability impact (CVSS 3.1: 9.8). All Kentico 9.x releases and 10.0.x, 11.0.x, and 12.0.x branches prior to the fixed builds (10.0.52, 11.0.48, 12.0.15) are affected. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), carries a very high EPSS score of 95.1%, and a public proof-of-concept for Kentico CMS 12.0.14 remote command execution is available.

Do: Upgrade affected instances immediately: 12.x to 12.0.15 or later, 11.x to 11.0.48 or later, and 10.x to 10.0.52 or later; for 9.x, apply the vendor-provided patch per Kentico's update instructions. Until patched, restrict access to the staging service (limit it to trusted internal networks/synchronization peers) and review logs for unauthenticated or anomalous requests to the staging endpoint.

9.895% KEV PoC
  • Kentico Xperience (Kentico CMS) 9.x (all); 10.0.x before 10.0.52; 11.0.x before 11.0.48; 12.0.x before 12.0.15
large≈tens of thousands of deployments (commercial enterprise CMS, commonly tens of thousands of licensed sites, with the staging service often internet-reachable)
CVE-2019-9879
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed.

The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

NVD description · AI analysis pending
9.847% PoC ×3
  • wpengine wpgraphql
CVE-2020-10188
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overfl

utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.

NVD description · AI analysis pending
9.874%
  • netkit telnet project netkit telnet
  • netkit telnet project fedora
  • netkit telnet project debian linux
  • +1 more
CVE-2020-1472
Unauthenticated Privilege Escalation (Zerologon) in Microsoft Netlogon Domain Controllers

CVE-2020-1472, widely known as "Zerologon," is an elevation-of-privilege flaw in how the Netlogon secure channel is established over the Netlogon Remote Protocol (MS-NRPC) on Microsoft domain controllers. An unauthenticated attacker with network reachability to a domain controller sends specially crafted Netlogon messages to establish a vulnerable secure channel and then runs a specially crafted application on the network to obtain domain administrator access. Successful exploitation yields domain administrator privileges, effectively full compromise of the Active Directory environment, and the flaw is known to be used in ransomware operations. Any organization running affected Windows Server versions (2008 through 20H2) as domain controllers is exposed, along with environments using Netlogon implementations from Samba and distributions or products from Fedora, openSUSE, Canonical (Ubuntu), Debian, Synology, and Oracle. Exploitation is highly active: a public Zerologon PoC/exploit is available, the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, with known ransomware use), and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Apply the vendor updates on all domain controllers and other affected systems immediately, following Microsoft's two-phase Netlogon secure channel guidance (the enforcement phase of the phased rollout began in Q1 2021). Audit Netlogon secure-channel connections and event logs for clients still using vulnerable connections before enabling full enforcement, and install updated packages for Samba and other Netlogon implementations from Fedora, openSUSE, Ubuntu, Debian, Synology, and Oracle. Given known ransomware use, prioritize patching any domain controller reachable from user networks, VPNs, or the internet.

5.599% KEV ransomware PoC
  • Microsoft Windows Server (when acting as a domain controller)
  • Samba (Netlogon secure channel implementation)
  • Fedora Project Fedora Linux
  • +5 more
massmillions of domain controllers worldwide (essentially every Active Directory domain), with hundreds of thousands of domain controllers/RPC endpoints…
Full article431 words · extracted from therecord.media · click to collapse

The US Federal Bureau of Investigation says that a threat actor known to be associated with Iran is currently seeking to acquire data from organizations across the globe, including US targets.

The actor has demonstrated interest in leaked data sets in various locations, including web forums and the dark web. The FBI judges this actor may attempt to leverage information in these leaked data sets, such as network information and email correspondence, to conduct their own cyber operations against US organizations.

FBI Private Industry Notification 20211108-001

The FBI said the threat actor wasn't interested in a particular industry vertical but was seeking data in bulk.

"This actor has also demonstrated interest in obtaining unauthorized access to SCADA systems using common default passwords," the agency added.

The FBI is now asking companies that have been at the center of a past hack where the data was leaked online to ensure that the leaked data can't be abused to breach them again.

This includes patching systems exploited in the last hack, resetting passwords, warning employees, and protecting internet-exposed systems.

In addition, the FBI also released a collection of tactics, techniques, and procedures (TTPs) that the Iranian threat actor has leveraged in the past:

  • Using auto-exploiter tools to build up a network of compromised WordPress sites for possible use as an RDP-scanning botnet, or to enable webshell access to targeted organizations. 
  • Using SQLmap to bypass Web Application Firewalls. 
  • Exploitation of the Kentico Content Management System. 
  • Attempting to enable Remote Desktop Protocol (RDP) on victim machines. 
  • Leveraging routers which may already have port-forwarding enabled for RDP. 
  • Brute forcing RDP. 
  • Using RDP port forwarding in conjunction with webshells, including the use of Tunna. 
  • Re-directing the home page or a '404' page in a site using WordPress.
  • Exploitation or interest in exploiting vulnerabilities tracked as CVE-2019-10068 (Kentico CMS), CVE-2008-3362 (WP Downloads Manager), CVE-2014-4725 (MailPoet Newsletters), CVE-2014-9735 (ThemePunch Slider Revolution), CVE-2015-1579 (Elegant Themes Divi theme), CVE-2015-4455 (Aviary Image Editor Add-on For Gravity Forms), CVE-2019-9879 (WPGraphQL), CVE-2015-8562 (Joomla CMS), CVE-2018-13379 (Fortinet), CVE-2020-10188 (Telnet), CVE-2020-1472 (Windows Netlogon).
  • The use of VPNs to mask their location, using ervices, such as Private Internet Access, Atlas VPN, TiKNet VPN, VPN Master Lite, and CyberGhost.

The FBI PIN alert was market TLP:Amber, meaning we can't publicly share it, as it was only sent to organizations the FBI believes would be targeted.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/fbi-iranian-threat-actor-trying-to-acquire-leaked-data-on-us-organizations