ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 478 by Pierluigi Paganini

criticalRansomware exploited in the wildimportance 60CVE-2024-28995CVE-2024-5806

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-28995
Unauthenticated Path Traversal File-Read in SolarWinds Serv-U

CVE-2024-28995 is a directory traversal flaw (CWE-22) in SolarWinds Serv-U, the vendor's managed file transfer/FTP server. Per the CVSS vector, it is reachable over the network with low attack complexity and requires no privileges or user interaction, meaning an unauthenticated remote attacker can trigger it. By sending traversal sequences that escape the intended directory, the attacker gains the ability to read sensitive files on the host machine (high confidentiality impact, with no integrity or availability impact). Any organization running SolarWinds Serv-U is potentially affected, particularly instances exposed to the internet. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-17, threat actors were reported exploiting it in the wild, and EPSS puts the 30-day exploitation probability at 99.6%, although no public proof-of-concept is known.

Do: Apply SolarWinds' patch or hotfix for Serv-U per the vendor's July 2024 PSIRT advisory, prioritizing internet-facing instances; if mitigations cannot be applied, CISA's required action is to follow vendor instructions or discontinue use of the product. In the meantime, restrict Serv-U exposure to trusted networks and review FTP/web server access logs for traversal-style requests that could indicate file reads or exfiltration.

7.5100% KEV
  • SolarWinds Serv-U
largelow tens of thousands of internet-exposed Serv-U file-transfer servers
CVE-2024-5806
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer:

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

NVD description · AI analysis pending
9.881%
  • progress moveit transfer
Full article426 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini June 30, 2024

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

Infosys McCamish Systems data breach impacted over 6 million people
A cyberattack shut down the University Hospital Centre Zagreb in Croatia
US announces a $10M reward for Russia’s GRU hacker behind attacks on Ukraine
New P2Pinfect version delivers miners and ransomware on Redis servers
New MOVEit Transfer critical bug is actively exploited
New Caesar Cipher Skimmer targets popular CMS used by e-stores
Mirai-like botnet is exploiting recently disclosed Zyxel NAS flaw
Wikileaks founder Julian Assange is free
CISA confirmed that its CSAT environment was breached in January.
Threat actors compromised 1,590 CoinStats crypto wallets
Experts observed approximately 120 malicious campaigns using the Rafel RAT
LockBit claims the hack of the US Federal Reserve
Ransomware threat landscape Jan-Apr 2024: insights and challenges
ExCobalt Cybercrime group targets Russian organizations in multiple sectors
Threat actor attempts to sell 30 million customer records allegedly stolen from TEG
Security Affairs newsletter Round 477 by Pierluigi Paganini – INTERNATIONAL EDITION
Threat actors are actively exploiting SolarWinds Serv-U bug CVE-2024-28995

International Press – Newsletter

Cybercrime  

Hacker claims to have 30 million customer records from Australian ticket seller giant TEG   

US convicts crypto-robbing gang leader who kidnapped victims before draining their accounts

Evolve Bank Data Leaked After LockBit’s ‘Federal Reserve Hack’  

4 FIN9-linked Vietnamese Hackers Indicted in $71M U.S. Cybercrime Spree

Malware

ExCobalt: GoRed, the hidden-tunnel technique  

RAFEL RAT, ANDROID MALWARE FROM ESPIONAGE TO RANSOMWARE OPERATIONS  

Decoding the Caesar Cipher Skimmer  

From Dormant to Dangerous: P2Pinfect Evolves to Deploy New Ransomware and Cryptominer

Medusa Reborn: A New Compact Variant Discovered     

Hacking

Chemical Security Assessment Tool (CSAT) Ivanti Notification  

Auth. Bypass In (Un)Limited Scenarios – Progress MOVEit Transfer (CVE-2024-5806)  

Polyfill Domain Shut Down as Owner Disputes Accusations of Malicious Activity

Intelligence and Information Warfare 

Russian National Charged for Conspiring with Russian Military Intelligence to Destroy Ukrainian Government Computer Systems and Data

Largest Croatian hospital under cyberattack    

Russian APT Reportedly Behind New TeamViewer Hack    

Kimsuky deploys TRANSLATEXT to target South Korean academia  

Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware

Cybersecurity  

Perplexity Plagiarized Our Story About How Perplexity Is a Bullshit Machine   

Sanctions Six Russian Hackers 

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/165020/breaking-news/security-affairs-newsletter-round-478-by-pierluigi-paganini-international-edition.html