Security Affairs newsletter Round 478 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-28995 | Unauthenticated Path Traversal File-Read in SolarWinds Serv-U CVE-2024-28995 is a directory traversal flaw (CWE-22) in SolarWinds Serv-U, the vendor's managed file transfer/FTP server. Per the CVSS vector, it is reachable over the network with low attack complexity and requires no privileges or user interaction, meaning an unauthenticated remote attacker can trigger it. By sending traversal sequences that escape the intended directory, the attacker gains the ability to read sensitive files on the host machine (high confidentiality impact, with no integrity or availability impact). Any organization running SolarWinds Serv-U is potentially affected, particularly instances exposed to the internet. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-17, threat actors were reported exploiting it in the wild, and EPSS puts the 30-day exploitation probability at 99.6%, although no public proof-of-concept is known. Do: Apply SolarWinds' patch or hotfix for Serv-U per the vendor's July 2024 PSIRT advisory, prioritizing internet-facing instances; if mitigations cannot be applied, CISA's required action is to follow vendor instructions or discontinue use of the product. In the meantime, restrict Serv-U exposure to trusted networks and review FTP/web server access logs for traversal-style requests that could indicate file reads or exfiltration. | 7.5 | 100% | KEV |
| largelow tens of thousands of internet-exposed Serv-U file-transfer servers | |
| CVE-2024-5806 | Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2. NVD description · AI analysis pending | 9.8 | 81% |
| — |
Full article426 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
June 30, 2024

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Cybercrime
Hacker claims to have 30 million customer records from Australian ticket seller giant TEG
US convicts crypto-robbing gang leader who kidnapped victims before draining their accounts
Evolve Bank Data Leaked After LockBit’s ‘Federal Reserve Hack’
4 FIN9-linked Vietnamese Hackers Indicted in $71M U.S. Cybercrime Spree
Malware
ExCobalt: GoRed, the hidden-tunnel technique
RAFEL RAT, ANDROID MALWARE FROM ESPIONAGE TO RANSOMWARE OPERATIONS
Decoding the Caesar Cipher Skimmer
From Dormant to Dangerous: P2Pinfect Evolves to Deploy New Ransomware and Cryptominer
Medusa Reborn: A New Compact Variant Discovered
Hacking
Chemical Security Assessment Tool (CSAT) Ivanti Notification
Auth. Bypass In (Un)Limited Scenarios – Progress MOVEit Transfer (CVE-2024-5806)
Polyfill Domain Shut Down as Owner Disputes Accusations of Malicious Activity
Intelligence and Information Warfare
Russian National Charged for Conspiring with Russian Military Intelligence to Destroy Ukrainian Government Computer Systems and Data
Largest Croatian hospital under cyberattack
Russian APT Reportedly Behind New TeamViewer Hack
Kimsuky deploys TRANSLATEXT to target South Korean academia
Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware
Cybersecurity
Perplexity Plagiarized Our Story About How Perplexity Is a Bullshit Machine
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/165020/breaking-news/security-affairs-newsletter-round-478-by-pierluigi-paganini-international-edition.html