ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 430 by Pierluigi Paganini

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-30799
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue.

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.

NVD description · AI analysis pending
7.21%
  • mikrotik routeros
CVE-2023-38408
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarde

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

NVD description · AI analysis pending
9.880% PoC ×3
  • openbsd openssh
  • openbsd fedora
CVE-2023-38606
Kernel State-Tampering Flaw in Apple iOS, iPadOS, macOS, tvOS and watchOS

CVE-2023-38606 is a kernel vulnerability in Apple's iOS, iPadOS, macOS, tvOS and watchOS, caused by a state-management defect that allowed an app running on the device to modify sensitive kernel state; Apple fixed it with improved state management in its July 2023 updates. Exploitation is local and requires user interaction (a user must run a malicious app), and successful exploitation lets the attacker alter protected kernel state, with the CVSS scoring high integrity impact but no direct confidentiality or availability loss. Apple stated the issue may have been actively exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-07-26; related reporting around this period links 2023 Triangulation-campaign exploit code to recent mass attack activity via the 'Coruna' iOS exploit kit. All users of iPhones, iPads, Macs, Apple TVs and Apple Watches running software older than the July 2023 patched releases (iOS 15.7.8/16.6, iPadOS 15.7.8/16.6, macOS 11.7.9/12.6.8/13.5, tvOS 16.6, watchOS 9.6) are affected.

Do: Update all affected devices to the patched releases: iOS 16.6 or iOS 15.7.8, iPadOS 16.6 or 15.7.8, macOS Ventura 13.5 / Monterey 12.6.8 / Big Sur 11.7.9, tvOS 16.6, and watchOS 9.6. No workarounds are documented; because the flaw is triggered by apps, users on unpatched devices should avoid installing or running untrusted apps. The CVE is in the CISA KEV catalog (added 2023-07-26), so federal agencies must apply the vendor fixes within the required BOD 22-01 timelines.

5.53% KEV
  • apple iPhone OS (iOS) iOS versions prior to iOS 15.7.8 and iOS 16 versions prior to iOS 16.6 (fixed in iOS 15.7.8 and iOS 16.6)
  • apple iPadOS iPadOS versions prior to 15.7.8 and iPadOS 16 versions prior to 16.6 (fixed in iPadOS 15.7.8 and iPadOS 16.6)
  • apple macOS Big Sur versions prior to 11.7.9 (fixed in macOS Big Sur 11.7.9)
  • +4 more
mass>1 billion active Apple devices (Apple reported an installed base exceeding 2 billion active devices in 2023)
CVE-2023-38750
In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed.

In Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41, 9 before 9.0.0 Patch 34, and 10 before 10.0.2, internal JSP and XML files can be exposed.

NVD description · AI analysis pending
7.5<1%
  • zimbra zimbra
Full article564 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini July 30, 2023

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

Now Abyss Locker also targets VMware ESXi servers
Russian APT BlueBravo targets diplomatic entities with GraphicalProton backdoor
CoinsPaid blames North Korea-linked APT Lazarus for theft of $37M worth of cryptocurrency
Monitor Insider Threats but Build Trust First
Zimbra fixed actively exploited zero-day CVE-2023-38750 in ZCS
DepositFiles exposed config file, jeopardizing user security
GROUP-IB Co-Founder ILYA SACHKOV SENTENCED TO 14 YEARS IN A STRICT PRISON COLONY
Two flaws in Linux Ubuntu affect 40% of Ubuntu users
Two ambulance services in UK lost access to patient records after a cyber attack on software provider
FraudGPT, a new malicious generative AI tool appears in the threat landscape
CISA adds Ivanti EPMM flaw to its Known Exploited Vulnerabilities catalog
Over 500K MikroTik RouterOS systems potentially exposed to hacking due to critical flaw
Atlassian addressed 3 flaws in Confluence and Bamboo products
VMware addressed an information disclosure flaw in VMware Tanzu Application Service for VMs and Isolation Segment
Apple addressed a new actively exploited zero-day tracked as CVE-2023-38606
Twelve Norwegian ministries were hacked using a zero-day vulnerability
A flaw in OpenSSH forwarded ssh-agent allows remote code execution
Apple could opt to stop iMessage and FaceTime services due to the government’s surveillance demands

Cybercrime

The shadow of Moscow extends over Brazil: from the scandal over the shelter of the Russian spy, to cyber-espionage and the sale of oil  

First Known Targeted OSS Supply Chain Attacks Against the Banking Sector

FraudGPT: The Villain Avatar of ChatGPT  

Ambulance patient records system hauled offline for cyber-attack probe  

ALPHV ransomware adds data leak API in new extortion strategy

Healthcare files of 8M-plus people fall into hands of Clop via MOVEit mega-bug

Lazarus hackers linked to $60 million Alphapo cryptocurrency heist

Malware

Who and What is Behind the Malware Proxy Service SocksEscort?      

Into the tank with Nitrogen 

Conti and Akira: Chained Together  

Linux version of Abyss Locker ransomware targets VMware ESXi servers

Sneaky XWorm Uses MultiStaged Attack

Related CherryBlos and FakeTrade Android Malware Involved in Scam Campaigns  

CISA Releases Malware Analysis Reports on Barracuda Backdoors

Hacking

Norwegian Ministries exposed to computer attacks  

A flaw in #OpenSSH forwarded ssh-agent allows remote code execution

Apple Rolls Out Urgent Patches for Zero-Day Flaws Impacting iPhones, iPads and Macs   

CVE-2023-38408: Remote Code Execution in OpenSSH’s forwarded ssh-agent  

Exploiting MikroTik RouterOS Hardware with CVE-2023-30799

GameOver(lay): Easy-to-exploit local privilege escalation vulnerabilities in Ubuntu Linux affect 40% of Ubuntu cloud workloads  

TETRA radio comms used by emergency heroes easily cracked, say experts


Intelligence and Information Warfare

CoinsPaid is back to processing after being hit by a hacker attack. Client funds were not affected and are fully available  

Moldova to kick out Russian diplomats over espionage allegations  

BlueBravo Adapts to Target Diplomatic Entities with GraphicalProton Malware    

Cybersecurity

Apple slams UK surveillance-bill proposals 

Think tank calls for monitoring of Chinese AI-enabled products

Cyber Command, NSA pick advances to Senate floor, but path to confirmation remains blocked   

US Senator Wyden Accuses Microsoft of ‘Cybersecurity Negligence’

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/148955/breaking-news/security-affairs-newsletter-round-430-by-pierluigi-paganini-international-edition.html