CISA, US Coast Guard warn of Log4Shell attacks after 130GB data breach in May
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44228 | JNDI Injection Remote Code Execution in Apache Log4j2 (Log4Shell) Apache Log4j2, an extremely widely used Java logging library, fails to protect its JNDI lookup feature against attacker-controlled JNDI-related endpoints (CWE-20, CWE-502), so crafted text processed by the logger causes the Java runtime to fetch and load attacker-supplied objects, leading to remote code execution. The flaw is triggered whenever attacker-controlled input reaches the logging API and is parsed for JNDI lookups, a pattern common in web servers and enterprise Java applications that log user-supplied fields such as headers or form values. Successful exploitation yields arbitrary code execution under the privileges of the affected application, giving attackers a foothold for lateral movement, data theft, and ransomware deployment. Any Java application or product that ships or bundles an affected Apache Log4j2 release is exposed, making this one of the most broadly deployed vulnerabilities ever disclosed. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days. Do: Inventory all Java applications and dependencies for Apache Log4j2 and apply the vendor's patched updates, or remove affected assets from the network, as required by CISA's KEV catalog. Where updates are not yet available, use the temporary mitigations in CISA's ED-22-02 recommended-mitigation guidance, such as disabling message lookups, only until patches are applied. Prioritize internet-facing and business-critical systems and hunt for exploitation activity given known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×9 |
| masshundreds of millions of Java applications/devices, with hundreds of thousands of internet-exposed services | |
| CVE-2022-22954 | Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager CVE-2022-22954 is a server-side template injection vulnerability (CWE-94) in VMware Workspace ONE Access and VMware Identity Manager that allows remote code execution on affected appliances. It is triggered when attacker-controlled input is passed into a server-side template engine, allowing injected template directives to be evaluated and executed as code on the server. A successful attacker gains the ability to run arbitrary code on the identity appliance, and CISA notes the flaw has been used in ransomware campaigns, so compromise can serve as an initial foothold for broader enterprise intrusion. Any organization running Workspace ONE Access or Identity Manager, including deployments where the Identity Manager component is bundled into VMware Horizon environments, is potentially affected, though the source data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-14 with ransomware use confirmed and a required action to apply vendor updates, and EPSS currently assigns it a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known. Do: Apply the patches published in VMware advisory VMSA-2022-0011 (April 2022) to Workspace ONE Access and Identity Manager appliances as required by the CISA KEV listing, prioritizing internet-facing instances, and restrict or remove public exposure until patched. Review appliance and web-server logs for template-injection probes and unexpected processes spawned by the identity service, and investigate any indications of compromise for follow-on ransomware or lateral-movement activity. | 9.8 | 100% | KEV ransomware PoC |
| large≈ tens of thousands of internet-exposed Workspace ONE Access / Identity Manager instances (order-of-magnitude estimate; exact count unknown) |
Full article775 words · extracted from therecord.media · click to collapse
The Cybersecurity and Infrastructure Security Agency (CISA) and the United States Coast Guard Cyber Command (CGCYBER) warned organizations that unpatched VMWare Horizon and Unified Access Gateway (UAG) servers are still being exploited through CVE-2021-44228 – known widely as Log4Shell. The government agencies said the vulnerability is being used in attacks by a range of threat actors, including state-backed groups. In an alert published on Thursday, the agencies included detailed rundowns of two different incidents affecting unnamed organizations where CVE-2021-44228 was exploited. “As part of this exploitation, suspected APT actors implanted loader malware on compromised systems with embedded executables enabling remote command and control (C2),” the agencies explained. “In one confirmed compromise, these APT actors were able to move laterally inside the network, gain access to a disaster recovery network, and collect and exfiltrate sensitive data.” In the second incident detailed in the alert, CISA said it was forced to conduct an "onsite incident response engagement." During the attack, which began in late April and continued through May, CISA said it discovered the organization had been “compromised by multiple threat actor groups.” One of the groups had been in the organization’s networks since January and may have been inside even earlier, according to CISA, which added that it gained access by exploiting Log4Shell in an unpatched VMware Horizon server. By January 30, one of the groups began using PowerShell scripts and eventually managed to move laterally to other production environment hosts and servers. The group was able to then use compromised administrator accounts to run a loader malware. “The loader malware appears to be modified versions of SysInternals LogonSessions, Du, or PsPing software. The embedded executables belong to the same malware family, are similar in design and functionality to 658_dump_64.exe, and provide C2 capabilities to a remote operator,” CISA said. “These C2 capabilities include the ability to remotely monitor a system's desktop, gain reverse shell access, exfiltrate data, and upload and execute additional payloads. The embedded executables can also function as a proxy.” CISA found that the threat actors were able to collect and exfiltrate more than 130GB of data from the organization over a three week period. The cybersecurity agency said it also found .rar files “containing sensitive law enforcement investigation data under a known compromised administrator account.” Another threat group gained access to the organization's test and production environments on or around April 13 and used CVE-2022-22954 to implant the Dingo J-spy webshell. CISA issued an emergency directive in May about CVE-2022-22954 after deploying an incident response team “to a large organization where the threat actors exploited” the recently-discovered remote code execution vulnerability affecting multiple VMware products. Check out this joint #cybersecurity advisory from @CISAgov & @USCG Cyber detailing cyber threat actors exploiting a #Log4Shell vulnerability in VMware Horizon® and Unified Access Gateway (UAG) servers to obtain access to victim networks. https://t.co/JYA5Ioz1fG pic.twitter.com/Do8qGI3YrW Any organizations that did not immediately apply the patches or workarounds for the vulnerability should “assume compromise and initiate threat hunting activities using the IOCs provided,” according to the advisory. Despite being discovered in December 2021, CISA included Log4Shell on its list of the top 15 routinely exploited vulnerabilities in 2021. In recent months, several cybersecurity firms have warned that Log4Shell is still an issue despite the global campaign to patch the vulnerability. Symantec said an unnamed engineering company with energy and military customers was hacked by the North Korean government using the Log4j vulnerability. Yotam Perkal, vulnerability researcher at cybersecurity firm Rezilion, released a report in April that found 55% of applications still contained an obsolete version of Log4j in their latest versions. About 90,000 machines and 68,000 public-facing internet servers were still vulnerable to Log4Shell, according to Perkal, who added that the time to patch the vulnerable containers exceeded 100 days and on average took 80 days. David Wolpoff, CTO of security company Randori, told The Record that Log4j “was one of the worst vulnerabilities I’ve seen in my career, and no doubt will have long-lasting impacts.” “The breadth of the issue and the difficulty in determining what was affected means that this will have a long tail to it,” Wolpoff explained. “Many of the impacted applications were also really critical applications: Vmware Horizon provides virtualized desktops; Jamf and Mobileiron provide device management (sometimes fleet-wide).”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-us-coast-guard-warn-of-log4shell-attacks-after-130gb-data-breach-in-may