ZeroHour
The Recordpublished ()ingested

Yamaha and WellLife Network confirm cyber incidents after ransomware gang claims attacks

highRansomwareimportance 60CVE-2023-3519

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-3519
Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway

CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations.

Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise.

9.8100% KEV ransomware PoC
  • Citrix NetScaler ADC Supported releases before the July 2023 fixes, per Citrix advisory: 14.1 before 14.1-8.50; 13.1 before 13.1-49.13; 13.0 before 13.0-82.45; 12.1 before 12.1-55.3
  • Citrix NetScaler Gateway Same affected builds as NetScaler ADC (before 14.1-8.50, 13.1-49.13, 13.0-82.45, 12.1-55.300, and FIPS/NDcPP equivalents); affected when the appliance serves as
largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream…
Full article514 words · extracted from therecord.media · click to collapse

Japanese manufacturer Yamaha Motor and the healthcare organization WellLife Network have confirmed cyberattacks after being added to the leak site of a ransomware gang this week.

Yamaha Motor published a notice on Thursday confirming that a server managed by its motorcycle manufacturing and sales subsidiary in the Philippines had been hit with a ransomware attack discovered on October 25.

The attack leaked the personal information of employees but the company noted that it will take more time before it understands the full extent of the damage.

The incident was reported to Philippine authorities on October 27 and on Thursday, the company confirmed that employee information was leaked.

“At present, servers and systems at YMPH not compromised by this attack have been restored. The attack was limited to one of the servers managed by YMPH and we have confirmed that it has not affected the headquarters or any other companies in the Yamaha Motor group,” the company said in a statement.

“However, we will continue to closely monitor the situation while continuing our work to fully restore the systems at YMPH damaged by the attack as quickly as possible.”

Yamaha Motor did not say which ransomware group attacked them but the INC ransomware gang posted the company to its leak site on Wednesday.

According to researchers at SentinelOne, the ransomware group emerged in July. Like several other extortion gangs, the group has been seen exploiting CVE-2023-3519 — a vulnerability affecting products from Citrix that has been part of a “large-scale exploitation campaign,” according to the Dutch Institute of Vulnerability Disclosure and cybersecurity firm Fox-IT.

SentinelOne noted that it has seen the group target multiple industries including education, government and healthcare.

On Friday, the group added WellLife Network to its list of victims. With an annual operating budget of $100 million, the organization provides a range of services to people with intellectual or developmental disabilities as well as those with mental illness.

On November 6, the organization posted a notice informing patients and employees that their IT team discovered a cyberattack in early September.

“The investigation is ongoing at this time. However, as of this writing, the investigation has determined that between August 26, 2023 and September 7, 2023, an unauthorized actor gained access to certain WellLife systems and may have viewed or taken certain information contained therein,” they said.

The information stolen includes names, dates of birth, demographic information, and other personal or health information.

They are still investigating the incident and plan to contact those affected, as well as state regulators. They did not respond to requests for comment about how many people were affected but in documents filed with the U.S. Department of Health and Human Services’ Office for Civil Rights, they said 501 people were impacted.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/yamaha-welllife-network-confirm-cyberattacks