ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

UK Cyber-Attacks Surge as Threats Hit Harder, Warns NCSC

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20198
Unauthenticated Privilege Escalation in Cisco IOS XE Web UI (Actively Exploited)

CVE-2023-20198 is a critical (CVSS 10.0) unauthenticated privilege escalation flaw in the web UI of Cisco IOS XE software, triggered by sending crafted network requests to the exposed web management interface. An attacker with no credentials can use the flaw to gain initial access and issue a privilege 15 command, creating a local user with normal login access; the attacker then chained CVE-2023-20273 (CVSS 7.2) to elevate that account to root and write an implant to the file system. Successful exploitation yields full administrative control of the device, including persistence via the planted implant, on Cisco IOS XE devices with the web UI enabled and reachable from the internet or untrusted networks, including Rockwell Automation Allen-Bradley Stratix 5200 and 5800 switches running IOS XE. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-16 with a BOD 23-02 directive, EPSS stands at 99.6% (100th percentile), and ongoing campaigns (including the 'BADCANDY' activity flagged by Australia's ASD and Cisco-related telecom intrusions attributed to Salt Typhoon) have been reported.

Do: Upgrade affected devices to the fixed releases listed in Cisco's advisory (use Cisco's Software Checker) and, as immediate mitigation, disable the web UI or restrict it to trusted networks/addresses only. Check for compromise by looking for unexpected local user accounts and the implant artifacts Cisco identified (unexpected cisco_tac_alarm.log and cisco_tac.log files in /tmp or /usr/binos/conf), and immediately report positive findings to CISA per BOD 23-02. Keep in mind that patching alone does not remove a root implant, so devices with evidence of compromise should be reimaged or otherwise cleaned per vendor instructions.

10.0100% KEV
  • Cisco IOS XE (Web UI feature)
  • Rockwell Automation Allen-Bradley Stratix 5200 firmware
  • Rockwell Automation Allen-Bradley Stratix 5800 firmware
large≈40,000–50,000 internet-exposed IOS XE devices at the time of disclosure (public scan data), within an IOS XE install base in the millions
CVE-2024-3400
Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect

Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Palo Alto Networks PAN-OS
large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled
Full article959 words · extracted from infosecurity-magazine.com · click to collapse

Cyber-attacks are becoming more frequent and severe, posing a greater risk to British organizations and the public, warned the UK’s National Cyber Security Centre (NCSC) in its latest Annual Review.

The report, published on December 3, shows that the NCSC’s Incident Management (IM) team has intervened 430 times out of the 1957 cyber-incident reports it received over the past year, exceeding the 371 needing the agency’s involvement in 2023.

Of these incidents, 89 were nationally significant, including 12 critical incidents – a threefold increase compared to last year.

Source: UK’s National Cyber Security Centre
Source: UK’s National Cyber Security Centre

Additionally, the IM team issued 542 bespoke notifications to UK organizations experiencing a cyber incident in 2024, over twice as many as the 258 bespoke notifications issued last year.

New NCSC Chief Urges Stronger Cyber Defenses

Richard Horne, NCSC’s new CEO, is expected to give his first-ever public speech in the role at an Annual Review launch event in London on December 3.

“What has struck me more forcefully than anything else since taking the helm at the NCSC is the clearly widening gap between the exposure and threat we face and the defenses that are in place to protect us,” he said in prepared remarks released ahead of the event, underscoring the urgent need for stronger cyber defenses and increased collaboration to address escalating threats. “And what is equally clear to me is that we all need to increase the pace we are working at to keep ahead of our adversaries.”

Horne believes most UK organizations, public and private, and the general public, are “widely underestimating” the country's cyber threats.

“We need all organizations, public and private, to see cybersecurity as both an essential foundation for their operations and a driver for growth. To view cybersecurity not just as a ‘necessary evil’ or compliance function, but as a business investment, a catalyst for innovation and an integral part of achieving their purpose.”

He is expected to announce that during his time in office, the NCSC will focus on translating previous NCSC guidance and frameworks into practice.  

"Defense and resilience of critical infrastructure, supply chains, the public sector and [the UK's] wider economy must improve."

Richard Horne, CEO, NCSC

Finally, Horne has told the press that “defense and resilience of critical infrastructure, supply chains, the public sector and [the UK’s] wider economy must improve.” 

Pat McFadden MP, Chancellor of the Duchy of Lancaster and Minister for Intergovernmental Relations, said in the report that one way of strengthening the UK’s defenses was by of doing this is by “driving up the adoption of our ‘Cyber Essentials’ scheme. Stats show those businesses who implement Cyber Essentials are 92% less likely to make a claim on their cyber insurance.”

“We are also working closely with businesses and industry through the NCSC and the National Protective Security Authority (NPSA) to offer practical ways that organizations can strengthen their own security and help defend the nation from cyber-attacks,” he added.

Ransomware, the Most Pervasive Threat to the UK

NCSC described ransomware as the most pervasive cyber threat to UK organizations.

Of the 542 bespoke notifications sent in by the IM team 2024, 317 were related to pre-ransomware activity, an increase on 297 in 2023.

These were triaged into 20 NCSC-managed incidents, of which 13 were nationally significant, including cyber-attacks against the British Library and several NHS trusts.

“The ransomware attack on Synnovis, and the impact this had on thousands of procedures and appointments across six NHS trusts, illustrates why – in our increasingly interconnected world – we must remain ahead of the threat,” Anne Keast‑Butler, Director of the UK Government Communications Headquarters (GCHQ), said in the report.

The top targets for ransomware activity in the UK were academia, manufacturing, IT, legal, charities and construction.

Over the last year, the IM team issued approximately 12,000 alerts about vulnerable services through its Early Warning service.

Exploitation of zero-days CVE-2023-20198 (Cisco IOS XE) and CVE-2024-3400 (Palo Alto Networks PAN-OS) also resulted in six nationally significant incidents for the IM team to manage.

Initiatives the NCSC has taken part in to curb the ransomware threat include a joint guidance on ‘ransom discipline’ developed in collaboration with the Information Commissioner’s Office (ICO) and the legal and insurance sectors to reduce the number of ransomware payments being made by victims of cybercrime and the Counter Ransomware Initiative (CRI), an international coalition of 40 members and eight insurance bodies.

Nation-State Campaigns More Frequent and With Greater Impact

Characterizing the 2024 cyber threat landscape as “diffuse and dangerous,” the Annual Review noted a rising frequency of cyber incidents and a growing severity in their impact, especially those coming from nation-state actors.

Over the past 12 months, the NCSC has observed how conflicts are fuelling a volatile threat landscape, including Russia’s deployment of destructive malware against Ukrainian targets and routine attempts to interfere with the systems of NATO countries in support of its war effort.

The Annual Review also noted that Moscow is increasingly inspiring non-state threat actors to carry out cyber-attacks against critical national infrastructure (CNI) in the UK and the Western world.

“These threat actors are not subject to formal or overt state control, which makes their activities less predictable. However, this does not lessen the Russian state’s responsibility for these ideologically driven attacks,” reads the report.

China is described as a highly sophisticated and capable actor targeting various sectors. In February 2024, the NCSC co-signed an advisory on observed compromises of US Critical National Infrastructure (CNI) by Volt Typhoon. In March 2024, the UK government called out China state-affiliated actors for targeting democratic institutions.

Iran-based threat actors remain aggressive in cyberspace, and North Korea continues to prioritize raising revenue to circumvent sanctions and collect intelligence in its cyber activity.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/uk-cyberattacks-surge-ncsc/